Skip to content
This repository has been archived by the owner on Sep 21, 2024. It is now read-only.

Patched on Windows 10 v21H2 Build 19044.1826 ? #12

Closed
GetRektBoy724 opened this issue Jul 17, 2022 · 8 comments
Closed

Patched on Windows 10 v21H2 Build 19044.1826 ? #12

GetRektBoy724 opened this issue Jul 17, 2022 · 8 comments
Labels
wontfix This will not be worked on

Comments

@GetRektBoy724
Copy link

GetRektBoy724 commented Jul 17, 2022

The payload DLL was not loaded, the program is running as Administrator and Im pretty sure architecture match and AV is not the problem. I also tested the program at Windows 10 v21H2 Build 19044.1288 and its still working fine.
image

@aaaddress1
Copy link

got the same problem here.

@itm4n
Copy link
Owner

itm4n commented Jul 20, 2022

Thank you @GetRektBoy724 for the heads up! 👍
I investigated this issue and I think I found why the payload DLL is not loaded anymore.
I will probably write a blog post about it.

@itm4n itm4n added the enhancement New feature or request label Jul 20, 2022
@GetRektBoy724
Copy link
Author

@itm4n Absolutely no problem, glad i can help. Waiting for the blog post :D

@itm4n
Copy link
Owner

itm4n commented Jul 24, 2022

The Known DLL trick was indeed fixed in the build version 10.0.19044.1826. My analysis here: https://itm4n.github.io/the-end-of-ppldump/.

@itm4n itm4n added wontfix This will not be worked on and removed enhancement New feature or request labels Jul 24, 2022
@xennn
Copy link

xennn commented Jul 29, 2022

The Known DLL trick was indeed fixed in the build version 10.0.19044.1826. My analysis here: https://itm4n.github.io/the-end-of-ppldump/.

Do you know if Microsoft has a KB patch for it? Or is it only present in the new build? There is nothing to be found at Microsoft about a patch for the NTDLL

@itm4n
Copy link
Owner

itm4n commented Jul 29, 2022

PP/PPL bypasses (even as a non-admin user) are not serviceable issues so I would imagine there is no associated KB. (See "Protected Process Light (PPL)" here: https://www.microsoft.com/en-us/msrc/windows-security-servicing-criteria).

@GetRektBoy724
Copy link
Author

@xennn this is the KB patch I guess. And as you can see there, the highlights are "Addresses security issues for your Windows operating system." and obviously Microsoft wouldn't say "A patch on NTDLL for preventing KnownDLLs hijacking on PP/PPLs processes" cause the public wouldn't understand 😂
https://support.microsoft.com/en-au/topic/july-12-2022-kb5015807-os-builds-19042-1826-19043-1826-and-19044-1826-8c8ea8fe-ec83-467d-86fb-a2f48a85eb41

@GetRektBoy724
Copy link
Author

And maybe, you can uninstall the KB patch update using wusa /uninstall /kb:HotFixID

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

4 participants