City
Epaper

Microsoft warns Windows users of unpatched critical bug

By IANS | Published: July 02, 2021 4:15 PM

San Francisco, July 2 Microsoft has warned Windows users of an unpatched critical vulnerability that can help hackers ...

Open in App

San Francisco, July 2 Microsoft has warned Windows users of an unpatched critical vulnerability that can help hackers install malicious programmes and access key data on their systems.

The critical flaw is present in the Windows Print Spooler service and is nicknamed 'PrintNightmare'.

The US national cyber agency has also admitted that the attacker can exploit 'PrintNightmare' to take control of an affected system.

"Microsoft is aware of and investigating a remote code execution vulnerability that affects Windows Print Spooler and has assigned CVE-2021-34527 to this vulnerability. This is an evolving situation," the company said in an update on Thursday.

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations.

"An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft warned.

Microsoft said, "The code that contains the vulnerability is in all versions of Windows".

The Print Spooler service runs by default on Windows, including on client versions of the OS, Domain Controllers, and many Windows Server instances.

Vulnerabilities in the Windows Print Spooler service have been a headache for system administrators for years.

The US Cybersecurity and Infrastructure Security Agency (CISA) has encouraged administrators to disable the Windows Print spooler service in Domain Controllers and systems that do not print.

Microsoft is working on a patch and has asked users to disable the Windows Print Spooler service, or disable inbound remote printing through Group Policy.

If you haven't installed the latest batch of Windows updates on your system, do so and disable the print spool service.

"Exploits such as this underline how important it is to both securely authenticate users and be in a position to identify unusual network activity," Martin Lee, technical lead at Cisco Talos, told The Registrar.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: National Cybersecurity and Communications Integration CenterusmicrosoftSan FranciscoSan francisco bayJose d'saMartin leeDemocratic party martin lee
Open in App

Related Stories

Other SportsWho Is Parvej Khan? All You Need to Know About the Indian Athlete Secure 1500m Final Spot in 2024 SEC Championships Relays

InternationalNew York Horror: Man Strangles Woman With Belt, Drags Her Between Cars To Rape; Disturbing CCTV Video Goes Viral

InternationalPower Outage in Mexico: Widespread Blackout Reported in Multiple Cities (Watch Video)

InternationalUS: 12-Year-Old Boy Receives World's First Commercially Approved Gene Therapy for Sickle Cell Disease

Social ViralTornado in US: Dashcam Records Terrifying Video of Cyclonic Storm Devastating Warehouse in Nebraska

Technology Realted Stories

TechnologyAfter seven years, WHO updates antibiotic-resistant bacteria list

TechnologyDelhivery posts Rs 69 crore net loss in Jan-March quarter, CBO Sandeep Barasia quits

Technology1 in 4 Indians faced cyber threat in Jan-March period: Report

TechnologyEU tells Microsoft to provide information on GenAI risks in Bing search else face fine

TechnologyWipro appoints Sanjeev Jain as COO as Amit Choudhary moves on