A critical severity vulnerability affecting the Windows Print Spooler Service, dubbed “PrintNightmare”, was treated with emergency patches by Microsoft. The vulnerability, initially believed to allow for escalation of privileges, was later discovered to also allow for remote code execution (RCE) attacks. If combined successfully, the vulnerabilities could allow for complete access to an organization’s infrastructure. Obstacles to fixing the issue were compounded by the accidental public exposure by researchers of a working proof of concept (PoC) for the exploit, which was reportedly cloned before it was removed. This event highlights the crucial role organizations such as Microsoft play in rapid remediation and the importance for researchers and defenders alike to remain diligent when developing PoCs.

×
Want these
Threat Intelligence reports sent straight to your inbox?
Subscribe below!
Thank you!
Error - something went wrong!
Most Recent Flipbooks
Weekly Intelligence Summary 21 October
Main story: Ransom Cartel and REvil: Partners in cybercrime?
Weekly Intelligence Summary 14 Oct
Main story: Hacktivists fan flames of Iranian anti-regime protests
Weekly Intelligence Summary 07 Oct
Main story: ProxyNotShell spells déjà vu for MS Exchange Server defenders
Weekly Intelligence Summary 30 Sept
Main story: Rogue ex-developer leaks LockBit 3.0 builder
Weekly Intelligence Summary 23 Sept
Main story: Uber compromised by Lapsus$'s resurgence
Weekly Intelligence Summary 16 Sept
Main story: Cyber attacks shock the Italian energy sector
Weekly Intelligence Summary 09 Sept
Main story: Back to school for students and ransomware groups
Weekly Intelligence Summary 02 Sept
Main story: LastPass suffers source code data breach