“PrintNightmare” Zero-Day Windows vulnerability

Content

Microsoft recently published patches for a vulnerability in the printer services in Windows. However, this vulnerability has not yet been fully closed so it can still be exploited. The vulnerability allows an attacker to execute code on any Windows computer that has the print spooler service turned on. This is the case with a standard installation.

An attacker with network access can gain system-level access to every Windows computer and server that uses the print spooler service. This vulnerability was rated by the NFIR CERT team with a Common Vulnerability Scoring System (CVSS) of 9.4, which represents a critical vulnerability. To mitigate the vulnerability, two measures can be taken. First, completely disabling the printer spoolers on all systems. If this is not possible, the second way is to change the permissions of the folder that the exploit code uses to ensure that the proof-of-concept code does not work. In any case, it is advised to keep Windows systems up-to-date. Read more about the scope and nature of the vulnerability and how to take effective mitigating vulnerabilities in this publication.

“PrintNightmare” Zero-Day Windows vulnerability

SECURITY INCIDENT BIJ UW ORGANISATIE?

De volgende 30 minuten van cruciaal belang​!

De eerste 30 minuten na een cyber security incident zijn cruciaal omdat snelle reactie de schade kan beperken, verdere verspreiding van de aanval kan voorkomen en essentieel bewijsmateriaal veiliggesteld kan worden voor onderzoek en herstel.

Onze Computer Emergency Response Teams (CERT) staan 24/7 klaar om bedrijven en organisaties te ondersteunen bij IT-beveiligingsincidenten.

Heeft uw bedrijf professionele hulp nodig bij een beveiligingsincident? 

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because rapid response can limit damage, prevent further spread of the attack and secure essential evidence for investigation and recovery.

Our Computer Emergency Response Teams (CERT) are available 24/7 to support businesses and organizations during IT security incidents.

Does your company need professional help with a security incident?