Microsoft just resolved the PrintNightmare vulnerability because it released the Windows August 10, 2021 Patch Tuesday security update.
On Wednesday, Microsoft released a patch that finally solved the PrintNightmare vulnerability that Windows 10 users encountered in the past few weeks. The update requires users to have administrative rights before gaining access to install printer drivers through the point and print function. Windows Central report.
“Today, we are addressing this risk by changing the default pointing and print driver installation and update behavior to require administrator privileges. Installing this update with default settings will mitigate publicly documented vulnerabilities in the Windows Print Spooler service,” Microsoft said. Blog post.
In June, a security researcher accidentally discovered the PrintNightmare vulnerability, a zero-day Windows print spooler. The vulnerability may provide local SYSTEM privileges by allowing remote code execution.
When exploited, the vulnerability may bring serious security risks to the device, because users with low privileges can use system privileges to open the command prompt. This allows them to directly access and control the equipment.
After analyzing the incident, Microsoft concluded that the PrintNightmare vulnerability points to the security level of the Point and Print function. The software giant stated that the default behavior of the feature does not provide sufficient security to protect users from potential attacks.
Microsoft launched an emergency update in July to address the PrintNightmare zero-day vulnerability. However, the patch did not completely solve the problem because it failed to prevent the local elevation of certain permissions.
“great #Patch tuesday Microsoft, but have you forgotten something #printnightmare? _
It is still SYSTEM from standard users…
(I may have missed something, but #mimikatz_mimispool library is still loading… _♂️) pic.twitter.com/OWOlyLWhHI“
-_said Benjamin Delpy (@gentilkiwi) August 10, 2021
In early August, researchers found a way to bypass the emergency update in July. Security researcher Benjamin Delpy discovered several ways to bypass the patch and exploit the PrintNightmare vulnerability.
Delpy found a print server that can install a print driver. The driver can start a dynamic link library that provides users with system permissions.
The update is recorded as CVE-2021-34481 and has been released for all versions of Windows. Microsoft urges Windows PC users to update their devices as soon as possible.
For users who want to allow non-advanced users to access the pointing and printing functions, they can use registry keys to do so, Digital Trend Report.
Photo: AFP/Fred Tanno



