Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
  1. Home
  2. News
  3. Security researchers release Windows zero-day exploit proof of concept

Security researchers release Windows zero-day exploit proof of concept

Jonny Caldwell Jonny Caldwell
October 24, 2018
2 min read

A new vulnerability was recently discovered in Windows 10 (via BleepingComputer) involving the Microsoft Data Sharing Service. The exploit was discovered by the pseudonymous SandboxEscaper, a former vulnerability researcher, and allows system library files to be deleted, forcing Windows to attempt to search for new libraries. This potentially puts a hacker in a spot to push fake malicious libraries in place of real ones. A successful exploit was also performed by Will Dormann, who shows the vulnerability is only in Microsoft’s latest Windows 10 system, not Windows 8.1 or any older iteration of Windows.

Confirmed as well on Win10 1803, fully-patched as of October.
It’s perhaps worth noting that the service used by the PoC, Data Sharing Service (dssvc.dll), does not seem to be present on Windows 8.1 and earlier systems. https://t.co/W8cNNC4xYO

— Will Dormann (@wdormann) October 23, 2018

Th vulnerability is present in both older and newer releases of Windows 10, including Microsoft’s recently pulled October 2018 Update, as well as Windows Server 2016 and 2019 operating systems. Luckily though, the exploit is difficult for hackers to take advantage of, according to SandboxEscaper and the risk is of “low quality,” although a successful hack can make the system completely unbootable.

Fortunately, the folks of 0patch have implemented their own fix for the issue which can be patched through their application, which available for download on their website. The application also provides patches for other system vulnerabilities, not just the one mentioned here. Microsoft regularly patches Windows, as well, and it may be best to just wait for the next official patch.

Share This Post:

Tags: Vulnerability | Windows 10
Share this article:
Tags:
Vulnerability Windows 10
Previous Article Want to know what Microsoft Search is all about? Here’s a quick overview Next Article Microsoft introduces new dark mode in Sticky Notes 3.1, fails

Related Articles

PlayStation’s PC Strategy Shift Came From Rising AAA Costs, Says Former Exec

PlayStation’s PC Strategy Shift Came From Rising AAA Costs, Says Former Exec

April 24, 2026

iPhone 18 Could Bring 12GB RAM, 2nm A20 Chip and Price Freeze

April 24, 2026

Discord Nitro May Add Xbox Game Pass Starter Edition With 50+ Games and Cloud Gaming Access

April 24, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • PlayStation’s PC Strategy Shift Came From Rising AAA Costs, Says Former Exec
  • iPhone 18 Could Bring 12GB RAM, 2nm A20 Chip and Price Freeze
  • Discord Nitro May Add Xbox Game Pass Starter Edition With 50+ Games and Cloud Gaming Access
  • Microsoft Drops ‘Microsoft Gaming’ Name, Brings Back Xbox Identity
  • Intel 14A Wins Tesla Deal, More Customers Show Interest

Recent Comments

  1. William on NZXT Responds to RTX 5090 Leak Claim, Disputes Redditor’s Version of Events
  2. Jenny Jones on Microsoft Publisher Will Shut Down in October 2026 and Users Are Not Happy
  3. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  4. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • PlayStation’s PC Strategy Shift Came From Rising AAA Costs, Says Former Exec
  • iPhone 18 Could Bring 12GB RAM, 2nm A20 Chip and Price Freeze
  • Discord Nitro May Add Xbox Game Pass Starter Edition With 50+ Games and Cloud Gaming Access
  • Microsoft Drops ‘Microsoft Gaming’ Name, Brings Back Xbox Identity
  • Intel 14A Wins Tesla Deal, More Customers Show Interest

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy