Software14.07.2016

20-year-old Windows printer flaw exposes you to malware

Windows logo

Security researchers from Vectra Networks recently found that the Windows Print Spooler does not properly authenticate printer drivers when you install them from a remote location, Ars Technica reported.

The vulnerability is rooted in a protocol called Point-and-Print, which lets you automatically download a printer’s driver when you connect to it for the first time over a network.

Point-and-Print stores a shared driver on the printer or print server so you don’t have to find, download, and install it manually.

Thanks to the vulnerability in the protocol, any printer, print server, or networked device pretending to be a printer may be used to deliver an exploit to unpatched Windows systems.

Microsoft included a fix for the issue in a patch this week, and in its advisory it rated the code-execution vulnerability critical for all supported Windows versions.

Vectra said the vulnerability dates back to Windows 95.

More on Windows

Windows Server 2016 launch details announced

Windows 10 Enterprise subscription licence prices revealed

What the new Windows 10 Start Menu looks like

You won’t miss this Windows 10 update notification

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter