Get a Pentest and security assessment of your IT network.

Cyber Security

Windows print nightmare continues with malicious driver packages

Microsoft’s print nightmare continues with another example of how a threat actor can achieve SYSTEM privileges by abusing malicious printer drivers. This technique can be used even if admins applied Microsoft’s recommended mitigations of restricting printer driver installation to admins and disabling Point and Print. Microsoft stated that their patches worked as intended, and as the vulnerability was being actively exploited, advised all Windows users to install the update. This method will likely not be fixed as Windows is designed to allow an administrator to install a printer driver even ones that may be unknowningly malicious.

Source: https://www.bleepingcomputer.com/news/microsoft/windows-print-nightmare-continues-with-malicious-driver-packages/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security