Company
Date Published
Author
Adam Foster
Word count
556
Language
English
Hacker News points
None

Summary

PrintNightmare is a remote code execution vulnerability in Microsoft systems that can be exploited by ransomware operators, allowing them to run arbitrary code with SYSTEM privileges and install programs, view or delete data, or create new accounts with full user rights. It was discovered by researchers at Tencent Security Xuanwu Lab and initially had a CVSS score of 8.8/8.2. The vulnerability is distinct from CVE-2021-1675, which has a lower CVSS score of 7.8/6.8. Microsoft released patches with the KB5003671 and KB5003681 updates in June 2021, but proof of concept was shown on Twitter by QiAnXin Technology on June 28th, 2021. The exploit has been implemented into security tools such as Mimikatz, and organizations can remediate the vulnerability by disabling the print spooler service or updating group policy to prevent client connections. Microsoft released an "Out of Bands" update for this vulnerability in KB5004954 and KB5004958 on July 6th, 2021.