Share to: share facebook share twitter share wa share telegram print page

PrintNightmare

PrintNightmare
CVE identifier(s)CVE-2021-1675
CVE-2021-34527
Date discoveredJune 29, 2021; 2 years ago (2021-06-29)
Date patchedJuly 6, 2021; 2 years ago (2021-07-06)[1]
DiscovererSangfor[2][3]
Affected softwareWindows Server 2012, Windows 7, Windows Server 2008, Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows 8, Windows 8.1, Windows Server 2022, Windows 10, Windows 11[4]

PrintNightmare is a critical security vulnerability affecting the Microsoft Windows operating system.[2][5] The vulnerability occurred within the print spooler service.[6][7] There were two variants, one permitting remote code execution (CVE-2021-34527), and the other leading to privilege escalation (CVE-2021-1675).[7][8] A third vulnerability (CVE-2021-34481) was announced July 15, 2021, and upgraded to remote code execution by Microsoft in August.[9][10]

On July 6, 2021, Microsoft started releasing out-of-band (unscheduled) patches attempting to address the vulnerability.[11] Due to its severity, Microsoft released patches for Windows 7, for which support had ended in January 2020.[11][12] The patches resulted in some printers ceasing to function.[13][14] Researchers have noted that the vulnerability has not been fully addressed by the patches.[15] After the patch is applied, only administrator accounts on Windows print server will be able to install printer drivers.[16] Part of the vulnerability related to the ability of non-administrators to install printer drivers on the system, such as shared printers on system without sharing password protection.[16]

The organization which discovered the vulnerability, Sangfor, published a proof of concept in a public GitHub repository.[3][17] Apparently published in error, or as a result of a miscommunication between the researchers and Microsoft, the proof of concept was deleted shortly after.[3][18] However, several copies have since appeared online.[3]

See also

References

  1. ^ "July 6, 2021—KB5004945 (OS Builds 19041.1083, 19042.1083, and 19043.1083) Out-of-band". Microsoft Support. Microsoft Corporation. Archived from the original on July 10, 2021. Retrieved July 11, 2021.
  2. ^ a b Valinsky, Jordan (July 9, 2021). "Microsoft issues urgent security warning: Update your PC immediately". CNN Business. Archived from the original on July 10, 2021. Retrieved July 11, 2021.
  3. ^ a b c d Corfield, Gareth (June 30, 2021). "Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller". The Register. Archived from the original on July 8, 2021. Retrieved July 11, 2021.
  4. ^ "Security Update Guide - Microsoft Security Response Center". msrc.microsoft.com. Retrieved June 17, 2024.
  5. ^ "Microsoft fixes critical PrintNightmare bug". BBC News. July 7, 2021. Archived from the original on July 10, 2021. Retrieved July 11, 2021.
  6. ^ Winder, Davey (July 2, 2021). "New Critical Security Warning Issued For All Windows Versions As 'PrintNightmare' Confirmed". Forbes. Archived from the original on July 11, 2021. Retrieved July 11, 2021.
  7. ^ a b "Security Update Guide - Microsoft Security Response Center". msrc.microsoft.com. Microsoft Corporation. Archived from the original on July 10, 2021. Retrieved July 11, 2021.
  8. ^ "Microsoft Releases Out-of-Band Security Updates for PrintNightmare". US-CERT. Cybersecurity and Infrastructure Security Agency. July 6, 2021. Archived from the original on July 7, 2021. Retrieved July 11, 2021.
  9. ^ "More PrintNightmare: 'We TOLD you not to turn the Print Spooler back on!'". Naked Security. July 16, 2021. Retrieved September 7, 2021.
  10. ^ "Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34481". msrc.microsoft.com. Retrieved September 7, 2021.
  11. ^ a b "Out-of-Band (OOB) Security Update available for CVE-2021-34527 – Microsoft Security Response Center". Microsoft Security Response Center. Microsoft Corporation. Archived from the original on July 10, 2021. Retrieved July 11, 2021.
  12. ^ Sharwood, Simon (July 7, 2021). "Microsoft patches PrintNightmare – even on Windows 7 – but the terror isn't over". The Register. Archived from the original on July 8, 2021. Retrieved July 11, 2021.
  13. ^ Smith, Adam (July 9, 2021). "Microsoft fixes huge security bug – and breaks people's printers". The Independent. Archived from the original on July 9, 2021. Retrieved July 11, 2021.
  14. ^ Lawler, Richard (July 8, 2021). "The Windows update to fix 'PrintNightmare' made some printers stop working". The Verge. Vox Media. Archived from the original on July 10, 2021. Retrieved July 11, 2021.
  15. ^ Goodin, Dan (July 8, 2021). "Microsoft Keeps Failing to Patch the Critical 'PrintNightmare' Bug". Wired. Condé Nast. Archived from the original on July 10, 2021. Retrieved July 11, 2021.
  16. ^ a b Mackie, Kurt (July 9, 2021). "Microsoft Clarifies Its 'PrintNightmare' Patch Advice -- Redmondmag.com". Redmondmag. 1105 Media Inc. Retrieved July 11, 2021.
  17. ^ Constantin, Lucian (July 8, 2021). "PrintNightmare Vulnerability Explained: Exploits, Patches, and Workarounds". ARN. IDG Communications. Archived from the original on July 8, 2021. Retrieved July 11, 2021.
  18. ^ Warren, Tom (July 2, 2021). "Microsoft warns of Windows "PrintNightmare" vulnerability that's being actively exploited". The Verge. Vox Media. Archived from the original on July 9, 2021. Retrieved July 11, 2021.


Baca informasi lainnya yang berhubungan dengan : article

Article 19 Article 20

Read other articles:

Kenturion Seorang kenturion (bahasa Latin: centurio; bahasa Yunani: κεντυρίων); bahasa Inggris: centurion), atau hekatontarkhos (ἑκατόνταρχος) pada sumber-sumber Yunani, atau pada zaman Bizantium, kentarkhos (κένταρχος) merupakan seorang perwira profesional pada Tentara Romawi setelah Reformasi Marian pada tahun 107 SM. Sebagian besar kenturion memimpin 83 orang meski dikira secara umum bahwa jumlahnya semestinya adalah 100. Tetapi para kenturion senior…

La morte di GiacintoAutoreGiambattista Tiepolo Data1752-53 Tecnicaolio su tela Dimensioni287×235 cm UbicazioneMuseo Thyssen-Bornemisza, Madrid La Morte di Giacinto è un dipinto olio su tela realizzato nel 1752-53 da Giambattista Tiepolo e conservato a Madrid nel Museo Thyssen-Bornemisza. Indice 1 Storia 2 Descrizione 3 Note 4 Bibliografia 5 Voci correlate 6 Altri progetti Storia Il quadro fu realizzato dall'artista in età matura, quando aveva ormai raggiunto una certa celebrità, rilevab…

Ini adalah nama Korea; marganya adalah Song. Pada nama panggung/nama pena, nama belakangnya adalah On. On Joo-wanOn Joo-wan pada bulan Februari 2012LahirSong Jeong-sik11 Desember 1983 (umur 39)Daejeon, Korea SelatanNama lainOhn Ju-wanPendidikanSeoul Institute of the Arts - BroadcastingPekerjaanAktorTahun aktif2004-sekarangNama KoreaHangul온주완 Hanja溫朱莞 Alih AksaraOn Ju-wanMcCune–ReischauerOn Chu-wanNama lahirHangul송정식 Hanja宋正植 Alih AksaraSong Jeong-si…

Cet article est une ébauche concernant le Luxembourg et le Concours Eurovision de la chanson. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. Luxembourgau Concours Eurovision 1975 Données clés Pays  Luxembourg Chanson Toi Interprète Géraldine Compositeur Phil Coulter, Bill Martin (en) Parolier Phil Coulter, Pierre Cour, Bill Martin Langue Français Sélection nationale Radiodiffuseur Télé Luxembourg…

Cotta–Cossebaude Streckenlänge:5,311 kmSpurweite:1450 mm Stromsystem:600 V =Zweigleisigkeit:Cossebauder/Warthaer Straße–Flensburger Straße Legende von Flügelweg von Altcotta Cossebauder/Warthaer Straße landwärts Cossebauder/Warthaer Straße stadtwärts nach Leutewitz Roquettestraße Stadtgrenze Dresden bis 1921 Schunckstraße Merbitzer Straße Zschonergrundstraße Zschonerbach Autobahn A 4 Bahnstrecke Berlin–Dresden Flensburger Straße Podemusstraße Am Urnenfeld Stadt…

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (مارس 2020) نجمية على سطح الياقوت الأزرق النجمية، هي ظاهرة الأحجار الكريمة التي تظهر تركيزًا يشبه النجم للضوء المنعكس أو المنكسر عند قطع الكابوشون (على شكل مصقول بدلاً من

Hiroshi InagakiEiga dan Engei (Moeie En d Entre rmenmen t, Asahi Shinbun, 1955Lahir(1905-12-30)30 Desember 1905Tokyo, JapanMeninggal21 Mei 1980(1980-05-21) (umur 74)Tokyo, JapanPekerjaansutradara, penulis latar, produser, aktorTahun aktif1923–1969PenghargaanGolden Lion1958 Rickshaw Man Hiroshi Inagaki (稲垣 浩code: ja is deprecated , Inagaki Hiroshi, 30 Desember 1905 – 21 Mei 1980) adalah seorang pembuat film Jepang yang paling dikenal karena Samurai I: Musashi Miyamoto yang mem…

يفتقر محتوى هذه المقالة إلى الاستشهاد بمصادر. فضلاً، ساهم في تطوير هذه المقالة من خلال إضافة مصادر موثوق بها. أي معلومات غير موثقة يمكن التشكيك بها وإزالتها. (يونيو 2019) الحدثكأس إيطاليا 1963–64 نادي روما نادي تورينو 1 0 التاريخ1 نوفمبر 1964  الملعبملعب تورينو الأولمبي  →نهائي…

تعدد الصيغ الصبغية (بالإنجليزية: polyploidy)‏ هي حالة تتميز باحتواء خلية الكائن الحي على أكثر من مجموعتين (متماثلتين) من الصبغيات. تعد غالبية الأنواع التي تمتلك نوى (حقيقيات النوى) ثنائية الصيغة الصبغية، أي أنها تحوي مجموعتين من الصبغيات، تُورث كل مجموعة من أحد الأبوين. لكن، تكون …

This article includes a list of references, related reading, or external links, but its sources remain unclear because it lacks inline citations. Please help to improve this article by introducing more precise citations. (March 2013) (Learn how and when to remove this template message) 1947 filmThe Nuremberg TrialsOpening screenDirected byElizaveta SvilovaProduced byRoman KarmenCinematographyRoman KarmenBoris MakaseyevS. SemionovV. ShtatlandEdited byA. VinogradovMusic byA. GranaDistributed byArt…

WhooshKereta api cepat Whoosh melintas di wilayah Kota BandungInformasi umumJenis layananKereta kecepatan tinggiDaerah operasi Provinsi Jawa Barat Kabupaten Bandung Kabupaten Bandung Barat Kabupaten Karawang Provinsi DKI Jakarta Kota Jakarta Timur Mulai beroperasi2 Oktober 2023; 2 bulan lalu (2023-10-02)Operator saat iniKereta Cepat Indonesia ChinaSitus webkcic.co.idLintas pelayananStasiun awalTegalluarJumlah pemberhentian4Stasiun akhirHalimJarak tempuh142,3 km (88 mi)Waktu tempuh…

Type of engine created by Toyota Reciprocating internal combustion engine Toyota ZR engine2ZR-FE engineOverviewManufacturerToyotaProduction2007–presentLayoutConfigurationStraight-fourCylinder block materialAluminiumCylinder head materialAluminiumValvetrainDOHC 4 valves x cyl. with VVT-iCombustionFuel systemFuel injectionFuel typeGasolineCooling systemWater-cooledOutputPower output98–217 hp (73–162 kW; 99–220 PS)Torque output153–207 N⋅m (113–153 lb⋅ft; 16

Placa costarriquenha emitida em 1961 As placas de registro de veículos na Costa Rica são a forma de identificação dos veículos motorizados no país centro-americano.[1] Tradicionalmente, as placas costarriquenhas são fabricadas no tamanho padrão norte-americano de 6 × 12 polegadas (152 × 300 mm). [2] [3] Galeria Esquematização das categorias de placas atualmente existentes na Costa Rica Referências ↑ http://www.worldlicenseplates.com/world/CE_COST.html ↑ http://www.plateshack.com…

Part of a series on theCulture of Qatar History People Languages Cuisine Festivals Public holidays Religion Art Collecting practices of the Al-Thani Family Public art in Qatar Literature Qatari folklore Music and Performing arts Media Radio Television Cinema Sport Monuments World Heritage Sites Symbols Flag Coat of arms National anthem vte Qatari literature traces its origins back to the 19th century. Originally, written poetry was the most common form of expression, but poetry later fell out of…

Supercopa Endesa 2019Datos generalesSede MadridRecinto Wizink CenterFecha 21 y 22 de septiembre de 2019Edición 20.ªPalmarésPrimero Real MadridSegundo BarçaMVP Facundo Campazzo Cronología 2018 2019 2020 [editar datos en Wikidata] La Supercopa de España de Baloncesto 2019 o Supercopa Endesa fue la 16.ª edición del torneo desde que está organizada por la ACB y la 20.ª desde su fundación.[1]​ Se disputó en el Wizink Center de Madrid durante los días 21 y 22 de septiembre…

Multiplayer online battle arena video game 2014 video gameVaingloryDeveloper(s)Super Evil MegacorpPublisher(s)Super Evil MegacorpPlatform(s)iOS, Android, Microsoft Windows, ChromeOS, macOSReleaseiOSNovember 16, 2014AndroidJuly 2, 2015Windows, MacJuly 29, 2018 (Alpha)February 13, 2019 (Full)Genre(s)MOBA Vainglory is a free-to-play video game with in-game purchases, developed and published by Super Evil Megacorp for iOS, Android and PC. The game is a version of the MOBA wherein two opposing teams …

For other novels, see Gladiator (disambiguation) § Literature. First UK editions (Penguin Books) Gladiator is a series of historical fiction novels for young adults by Simon Scarrow set in ancient Rome in the years before the fall of the Roman Republic. The books tell the story of Marcus Cornelius Primus, a young gladiator and street fighter caught up in the dramatic events unfolding as Rome descends into civil war and chaos. Titles in series Gladiator: Fight for Freedom Gladiator: Street …

Species of frog Boophis rappiodes Conservation status Least Concern (IUCN 3.1)[1] Scientific classification Domain: Eukaryota Kingdom: Animalia Phylum: Chordata Class: Amphibia Order: Anura Family: Mantellidae Genus: Boophis Species: B. rappiodes Binomial name Boophis rappiodes(Ahl, 1928) Synonyms Rhacophorus rappiodes Ahl, 1928 Boophis rappiodes is a species of frog in the family Mantellidae. It is endemic to Madagascar.[2] It occurs in the eastern and southern rainfor…

Place in Bosnia and HerzegovinaSarajevo Metropolitan Region Sarajevska Metropolitanska RegijaSatellite image of the Sarajevo Urban AreaCountry Bosnia and HerzegovinaThe Federation Sarajevo Canton Sarajevo Largest citySarajevo (275,524)Area • Metro3,351.28 km2 (1,293.94 sq mi)Population • Metro555,210 • Metro density165.7/km2 (429.1/sq mi)Time zoneUTC+1 (CET) The Sarajevo metropolitan area is the largest agglomeration in Bosnia and…

Fleetwood Mac discographyFleetwood Mac performing live in 2018Studio albums18Live albums10Compilation albums23Video albums11Music videos30EPs1Singles62Other charted songs8 The discography of British-American band Fleetwood Mac consists of 18 studio albums, 10 live albums, 23 compilation albums, one extended play and 62 singles. The band also has sold over 120 million records worldwide, making them one of the best-selling music artists of all time.[1] The 1967–1969 era Blue Horizon albu…

Kembali kehalaman sebelumnya