Windows 10, 11 Users Need 3rd-Party Patch for Security Vulnerability

Windows Vulnerability Patch Featured2

Microsoft has had plenty of time to fix a security vulnerability. After the vulnerability was disclosed, a patch was released, and it was proven not to be 100 percent successful. But a third-party security specialist has stepped in to develop a patch for the Windows 10 and 11 security vulnerability.

Windows Security Vulnerability Known Since August

Microsoft has a confirmed vulnerability in Windows 10, 11, and older versions, and it has known about it since August. The company appeared to fix it; however, the same security researcher who discovered the Windows User Profile Service 0day LPE vulnerability found the patch ineffective. The zero-day vulnerability can give hackers access, allowing them to take control of your Windows system.

Windows Vulnerability Patch System

Security researcher Abdelhamid Naceri reported the proof of concept, and Microsoft released a patch. However, Naceri found that hackers could get past the patch to get system privileges, providing all necessary components were covered. This led to an elevated command prompt when the User Account Control Prompt is shown.

Will Dormann, a CERT/CC vulnerability analyst, tested the patch and found that it worked. Yet, he also found that it didn’t always create the elevated command prompt.

While this flaw is definitely a threat to your Windows system, it requires hackers to know other users’ login details, meaning it can’t affect every system.

Windows Vulnerability Patch Keyboard

It was announced in October that Microsoft’s patch didn’t work. Yet, it’s November, and a new patch still hasn’t been released – by Microsoft.

0patch Releases a Security Patch

0patch, a third-party security specialist, stepped into the void to provide a fix. “Micropatches for this vulnerability will be free until Microsoft has issued an official fix,” announced 0patch.

Information in Naceri’s writeup and POC for the Windows User Profile Service 0Day LPE was used to develop the 0patch micropatch.

“While this vulnerability already has its CVE ID (CVE 2021-33742), we’re considering it to be without an official vendor fix and therefore a 0day,” shared Mitja Kolsek, 0patch co-founder. “Micropatches for this vulnerability will be free until Microsoft has issued an official fix.”

Windows Vulnerability Patch Microsoft

This serves as one of the few times that it won’t help to be working with the latest system update. While Microsoft’s fix was also found to be flawed, the flaw isn’t as damaging to older systems. All versions are vulnerable.

“The vulnerable code is different [in older Windows versions], making the windows for winning the race condition extremely narrow and probably exploitable,” said Kolsek

Nevertheless, staying updated is always a wiser idea than not. Once Windows does issue a fix or patch for the zero-day vulnerability, you’ll want to be using the latest version.

Learn how to install Windows 11 on your PC as well as what to do before and after the install.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.