Blog | G5 Cyber Security

CISA: Disable Windows Print Spooler on servers not used for printing

Chinese security company Sangfor accidentally leaked a proof-of-concept exploit for the zero-day Windows Print Spooler vulnerability known as PrintNightmare. The vulnerability allows attackers to take control of affected servers via remote code execution with SYSTEM privileges. US-CERT/CC has also published instructions on stopping and disabling the service in a separate Vulnerability Note. A video of the printNightmare exploit in action created by mimikatz developer Benjamin Delpy is embedded below. The leak was caused by confusion surrounding the vulnerability, which researchers thought was tracked as CVE-2021-1675.

Source: https://www.bleepingcomputer.com/news/security/cisa-disable-windows-print-spooler-on-servers-not-used-for-printing/

Exit mobile version