
0patch
@0patch
Followers
8K
Following
526
Media
412
Statuses
4K
Microscopic cures for big security holes. 0patch (pronounced 'zero patch') Bluesky: https://t.co/js7yaM3lqN Mastodon: @[email protected]
in every running process
Joined March 2012
We'd like to thank Filip Dragović (@filip_dragovic). for sharing their finding and their POC, which allowed us to reproduce the issue and create patches for our users.
0
6
12
We'd like to thank @moiz_hehe for sharing their finding and their POC, which allowed us to reproduce the issue and create patches for our users.
0
4
3
Our researchers have confirmed this issue on freshly installed fully updated Windows Server 2025 domain controller, using a regular domain user as attacker. Instant domain controller BSOD by any domain user.
Welp. reported an issue to msrc, demonstrating that kerberos TGS request with a malformed PA-FOR-X509-USER struct will crash the LSASS on any win2025 domain controller. Got the default response :/.Dunno how I feel abt this, but this was the first and last time I'm doing this.
1
9
31
We would like to thank security researchers Alexandra Gofman and David Driker with @_CPResearch_ for detecting the exploitation and publishing their analysis, which made it possible for us to create a micropatch for this issue.
0
4
1
We would like to thank security researcher Zhiniang Peng (@edwardzpeng) for publishing their analysis, which made it possible for us to create a micropatch for this issue.
0
3
5