Skip naar inhoud

PrintNightmare haunts Microsoft as patch may miss mark

Wilt u deze bijdrage aanbevelen? Dat kan via:

Microsoft dropped an out-of-band patch to fix PrintNightmare, but there are concerns it may not be totally effective. This does not mean it shouldn’t be applied
Microsoft released a rare out-of-band patch on 7 July to fix the so-called PrintNightmare vulnerability, but appears to have failed to address some fundamental aspects of the Windows Print Spooler bug, meaning even fully patched systems may still be at risk, according to researchers.

The background to the somewhat confusing saga is thus: Microsoft had first patched CVE-2021-1675, as a relatively low-priority local privilege escalation vulnerability in June’s Patch Tuesday drop, but it came to prominence last week when two Chinese researchers, concerned that rivals were getting the jump on their research, released a proof of concept (PoC) exploit for what they believed was CVE-2021-1675. It was not; in fact, the researchers had exposed a far more dangerous RCE zero-day, CVE-2021-34527, for which no patch was available.

Almost immediately after the patch dropped, security pros said they had found that while the patch addressed the RCE component of PrintNightmare quite nicely, it failed to cover users against LPE in some specific situations – meaning an attacker already on the network could still wreak havoc if they wanted. In effect, the patch seems to be incomplete.

Huntress’s John Hammond said that to date, the firm had not seen a patch scenario that encompassed preventing LPE, preventing RCE, and most crucially for users, allowed them to print normally.

Moreover, the patch does not yet address various Microsoft systems, namely Windows 10 version 1607, Windows Server 2012 and Windows Server 2016. Microsoft said this was an intentional choice.

In a blog post, Redmond said: “Some packages are not quite ready for release. We feel that it is important to provide security updates as quickly as possible for systems we can confidently protect today.”

Regardless of the effectiveness of the patch, users are still best advised to download and apply it, even though this may be somewhat disruptive to security team schedules around the July Patch Tuesday drop, which will happen on 13 July.

Tenable staff research engineer Satnam Narang said PrintNightmare warranted immediate attention because of the ubiquity of Windows Print Spooler, and the prospect attackers could exploit the flaw to take over a domain controller.

“While we do not know with certainty why Microsoft chose to publish this as an out-of-band patch, we suspect the availability of a number of proof-of-concept exploit scripts along with reports of in-the-wild exploitation contributed to this decision,” he said. We expect it will only be a matter of time before it is more broadly incorporated into attacker toolkits.

“PrintNightmare will remain a valuable exploit for cyber criminals as long as there are unpatched systems out there, and as we know, unpatched vulnerabilities have a long shelf life for attackers.

“Now that Microsoft has released patches, organisations are strongly encouraged to apply the patches as soon as possible, especially as attackers incorporate readily available PoC exploit scripts into their toolkits,” Narang told Computer Weekly in emailed comments.

Tim Mackey, principal security strategist at the Synopsys CyRC (Cybersecurity Research Centre), agreed: “Whenever there is a new security disclosure, it should be assumed that knowledge of how to exploit the weaknesses in the disclosure is known.

“It should also be understood that once information is published online that it will be cloned or copied by someone else. PoCs of exploitable security issues are commonly posted after the security disclosure and associated patches are made public.

“Publication is a normal process because those details might allow other security researchers to identify other paths to exploitation that might also need patching. For users, the best thing they can do to avoid falling victim is to patch their Windows systems promptly,” he said.

Lees ook:

Na sase komt sse (security service edge)

Security service edge (sse) is de evolutie van het sase-framework van Gartner. Door de letter ‘A’ (voor ’access) te verwijderen, wordt duidelijk dat het netwerk niet langer wordt beschouwd als onderdeel van een beveiligingsoplossing. Het is slechts het mechanisme dat de datastromen naar het security- en controleplatform transporteert.

UK tech has 2.8% gender ‘wage gap’, says Hired

The wage offered to women for tech jobs in the UK is 2.8% less than offered to male counterparts – a larger gap than in the US and Canada, says Hired

HPE bouwt eerste Europese supercomputerfabriek

Hewlett Packard Enterprise (HPE) zet in Tsjechië zijn eerste Europese productielijn voor supercomputers en ai-systemen neer. Elders in de wereld heeft het techbedrijf al drie van zulke fabrieken. De Tsjechische locatie moet de levering aan Europese klanten versnellen en het regionale netwerk van toeleveranciers versterken. Volgens het concern loopt Europa voorop bij de inzet van supercomputers en artificiële intelligentie (ai).

Government won’t regulate on professional cyber standards

The government has elected not to proceed with regulatory intervention to embed standards and pathways across the cyber profession

Slimmer datagebruik leidt tot forse efficiency

Bedrijven kunnen zeker tien procent efficiënter werken door slimmer gebruik te maken van de aanwezige informatie in digitale bedrijfsprocessen. ‘Er zit nog veel onbenut potentieel in de informatie uit de systemen’, zegt Remco Dijkman, professor in Information Systems aan de TU Eindhoven. Hij noemt het percentage een voorzichtige inschatting.

EasyComp Zeeland opent nieuwe online megastore EasyComp Shop.

EasyComp Zeeland, een toonaangevende leverancier van allerlei IT en ICT-dienstverlening, heeft vandaag haar nieuwe online megastore EasyComp Shop geopend. Deze one-stop-shop biedt een uitgebreid assortiment producten van wereldberoemde merken tegen scherpe prijzen. Of u nu op zoek bent naar een nieuwe laptop, tablet of smartphone, in de EasyComp Shop vindt u altijd wat u zoekt.

Wilt u deze bijdrage aanbevelen? Dat kan via:

Klaar voor de beste oplossing voor uw IT & ICT-situatie?

Ik heb mijn wachtwoord gewijzigd in “onjuist.” Dus wanneer ik vergeet wat het is, zal de computer zeggen: “Uw wachtwoord is onjuist.”