-
Notifications
You must be signed in to change notification settings - Fork 137
Patched on Windows 10 v21H2 Build 19044.1826 ? #12
Comments
got the same problem here. |
Thank you @GetRektBoy724 for the heads up! 👍 |
@itm4n Absolutely no problem, glad i can help. Waiting for the blog post :D |
The Known DLL trick was indeed fixed in the build version |
Do you know if Microsoft has a KB patch for it? Or is it only present in the new build? There is nothing to be found at Microsoft about a patch for the NTDLL |
PP/PPL bypasses (even as a non-admin user) are not serviceable issues so I would imagine there is no associated KB. (See "Protected Process Light (PPL)" here: https://www.microsoft.com/en-us/msrc/windows-security-servicing-criteria). |
@xennn this is the KB patch I guess. And as you can see there, the highlights are "Addresses security issues for your Windows operating system." and obviously Microsoft wouldn't say "A patch on NTDLL for preventing KnownDLLs hijacking on PP/PPLs processes" cause the public wouldn't understand 😂 |
And maybe, you can uninstall the KB patch update using |
The payload DLL was not loaded, the program is running as Administrator and Im pretty sure architecture match and AV is not the problem. I also tested the program at Windows 10 v21H2 Build 19044.1288 and its still working fine.
The text was updated successfully, but these errors were encountered: