Microsoft's incomplete PrintNightmare patch fails to fix vulnerability

backstreetboy

Honorary Master
Joined
Jun 15, 2011
Messages
49,397
Reaction score
56,416
Location
I'm so sorry—love, backstreetboy. God forgive me.

Researchers have bypassed Microsoft's emergency patch for the PrintNightmare vulnerability to achieve remote code execution and local privilege escalation with the official fix installed.

Last night, Microsoft released an out-of-band KB5004945 security update that was supposed to fix the PrintNightmare vulnerability that researchers disclosed by accident last month.

After the update was released, security researchers Matthew Hickey, co-founder of Hacker House, and Will Dormann, a vulnerability analyst for CERT/CC, determined that Microsoft only fixed the remote code execution component of the vulnerability.

However, malware and threat actors could still use the local privilege escalation component to gain SYSTEM privileges on vulnerable systems only if the Point and Print policy is enabled.

 
The S in PrintNightmare Patch stands for security.

...ok that was pretty bottom of the barrel lol
 
Otherwise than problems with printers, are there any other issues that this patch is causing? I like to wait a bit before updating but I don't like leaving big security updates waiting.
 
Top
Sign up to the MyBroadband newsletter
X