Microsoft releases fix for privilege escalation bug in Windows 8.1 and Server
Microsoft has released an unexpected patch for a vulnerability in Windows Remote Access. There was one privilege escalation in which was exploitable on Windows 8.1 and Windows Server 2012. The patch is only available for those operating systems.
Microsoft has now released emergency patch KB4578013 for all users of Windows 8.1, Windows RT 8.1 and Windows Server 2012 R2. “Users of other versions of Windows or Windows Server do not have to do anything,” writes Microsoft. The same vulnerability was already fixed on those other Windows versions in August Patch Tuesday.
The current patch fixes two vulnerabilities: CVE-2020-1530 and CVE-2020-1537. Both are privilege escalations in Windows Remote Access, specifically in the way that tool handles memory. To exploit the vulnerability, attackers had to be able to execute code on a victim’s system first.