Site icon TechGit

Windows 10 gets out-of-band patch for PrintNightmare vulnerability

Patch Tuesday isn’t until next Tuesday, but Windows is already getting cumulative updates this week. Microsoft is addressing a critical vulnerability in various Windows 10 versions, including the latest version 21H1, but also going back to the original Windows 10 release. The update is meant to address a Windows 10 vulnerability called PrintNightmare, which was disclosed last week. This vulnerability allows attackers to leverage the Windows Print Spooler service to take over an organization’s domain to spread malware.

Technical details and a proof-of-concept for the vulnerability were accidentally revealed because researchers conflated the vulnerability with another issue that was patched last week, which was labeled CVE-2021-1675. This latter issue was addressed in the Patch Tuesday update for Windows 10 June, but the PrintNightmare vulnerability wasn’t. They then published the technical details of exploiting the vulnerability before it was patched, leaving servers open to attacks. This prompted the Cybersecurity & Infrastructure Security Agency to encourage server admins to disable the Windows Print Spooler service.

The severity of this vulnerability and the accidental disclosure prompted Microsoft to quickly release a patch. The vulnerability is now identified as CVE-2021-34527, and it’s been patched in today’s out-of-band update. The update that fixes the issue is labelled KB5004945 if you’re using Windows 10 versions 21H1, 20H2, or 2004, and it’ll bring you to build number 19043.1083, 19042.1083, or 19041.83, respectively, for each of those versions. You can download the update manually here. This fix is pretty much all that’s new, and Microsoft has shared some detail on the vulnerability. Here’s what the changelog says:

For other versions, you can find the links to the KB articles and download links below:

Windows 10 version KB article Build number Download
1909 KB5004946 18363.1646 Update Catalog
1809 KB5004947 17763.2029 Update Catalog
1507 KB5004950 10240.18969 Update Catalog

This update is mandatory, so it’s available through Windows Update and it will install automatically. You can use the download links to get it faster, though. Of course, this doesn’t change the schedule for next week’s Windows updates. Those should include a lot more fixes, and they will also be mandatory.

The post Windows 10 gets out-of-band patch for PrintNightmare vulnerability appeared first on xda-developers.

FacebookTwitterTumblrRedditLinkedInHacker NewsDiggBufferGoogle ClassroomThreadsXINGShare
Exit mobile version