- Joined
- May 6, 2019
- Messages
- 12,595
- Points
- 113
Image: Microsoft
Microsoft pushed an emergency update to Windows users yesterday for “PrintNightmare,” a zero-day vulnerability that allows attackers to remotely execute code with system privileges on various versions of the operating system. Unfortunately, users are beginning to learn that the update is only partially effective. As discovered by security researchers Matthew Hickey and Will Dormann, Microsoft only fixed the remote code execution component of the vulnerability, allowing threat actors to continue leveraging the exploit by using the local privilege escalation component to gain system privileges for both older and newer Windows versions. This is possible on the latter if the Point and Print policy...
Continue reading...