Microsoft fixes PrintNightmare vulnerability but leaves it open to local attacks

Printer Spool vulnerability fixed
(Image credit: Pixabay - mohamed_hassan)

Microsoft has gone out of its way this week to fix a vulnerability known as 'PrintNightmare'. First officially acknowledged by Microsoft on July 1, according to Complete I.T. Blog, the vulnerability meant any instances where Microsoft Windows Print Spooler service was running, a PC would be left open to attackers, who could remotely execute malicious code at will.

The news of a fix to the vulnerability, filename CVE-2021-34527, came to our attention via @Msftsecresponse on Twitter:

Printers are a relatively common target for hackers trying to take control of machines, and once they find themselves with system privileges, they can easily shuffle your data, delete or copy important files, even create new accounts with admin rights, along with countless other sneaky activities.

Perfect peripherals

(Image credit: Colorwave)

Best gaming mouse: the top rodents for gaming
Best gaming keyboard: your PC's best friend...
Best gaming headset: don't ignore in-game audio

With one of the only workarounds being the system admin manually disabling the Print Spooler service—unhelpful if you need to use it on a daily basis—it comes as a great relief that Microsoft has finally rolled out a patch.

But the patch isn't a full fix, leaving Print Spooler users open still to local attacks. As noted by Tijs Hofmans over at tweakers, "It is still possible to perform a local privilege escalation. To prevent this, users can disable the Point&Print functionality."

You can find the Microsoft Windows Print Spooler security updates for here, anyway. Just be aware of any dodgy looking, probably hood-wearing characters using your local network. That's what hackers look like, right?

Katie Wickens
Hardware Writer

Screw sports, Katie would rather watch Intel, AMD and Nvidia go at it. Having been obsessed with computers and graphics for three long decades, she took Game Art and Design up to Masters level at uni, and has been rambling about games, tech and science—rather sarcastically—for four years since. She can be found admiring technological advancements, scrambling for scintillating Raspberry Pi projects, preaching cybersecurity awareness, sighing over semiconductors, and gawping at the latest GPU upgrades. Right now she's waiting patiently for her chance to upload her consciousness into the cloud.

Read more
Promotional image of the HP Envy Inspire inkjet printer
Haunted printers turning on by themselves and printing nonsense has to be one of my favorite Windows 11 bugs ever
Microsoft Windows 11
If you installed Windows 11 with certain security updates and a USB stick, you may not get any more security updates warns Microsoft
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
A photo of the Windows update menu, showing that I'm all up to date
Latest Windows 11 Insider Build fixes 24H2 update's most annoying issues, including Auto HDR bugs and mouse stuttering
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Netgear Nighthawk XR1000
Netgear says certain router owners should 'download the latest firmware as soon as possible' to patch a critical vulnerability
Latest in Hardware
A woman wearing a VR headset with dramatic, colourful lighting across the background
'World’s smallest LEDs' could lead to accurately lit screens with 127,000 pixels per inch and much more immersive VR
The NES themed 8BitDo Retro mechanical gaming keyboard on a blue background
I love the 8BitDo Retro C64 keyboard but I'd pick its cheaper NES-themed model near its lowest price ever during Amazon's Big Spring Sale
The snazzy red and black HyperX Cloud Alpha wireless headphones float in a teal void. The microphone is attached to the headset.
The best wireless gaming headset is now even better in the Amazon Big Spring Sale, boasting a more than $50 discount
A chip being held up in an Intel fab
Intel is reportedly 'working to finalize commitments from Nvidia' as a foundry partner, suggesting gaming potential for the 18A node
Amazon box
Don't panic! The 'Do Not Send Voice Recordings' option Amazon just removed was only used by 0.03% of customers and they can still have it
Digital generated image of people surrounded by interactive transparent and glowing panels with data. Visualising smart technology, blockchain and artificial intelligence
Now I shall demand the cookies! Proposed new browsing agreement turns the tables and lets users dictate terms to websites
Latest in News
An Enshrouded player in a recreation of Erebor from The Lord of the Rings
Kings under the Mountain! 33 Enshrouded players spent 10,000 hours to recreate this iconic location from The Lord of the Rings
A mech awakens.
Mecha Break developer is considering unlocking all mechs following open beta feedback
Lara Croft Unified Art
Tomb Raider developer Crystal Dynamics lays off 17 employees 'to better align our current business needs and the studio's future success'
A long bendy arm stealing money from people in a subway car
'You're a very long arm. You steal things. It's a comedy game,' explains developer of comedy game where you steal things with a very long arm
The heroes are attacked by monsters
Pillars of Eternity is getting turn-based combat to mark its 10th anniversary, and that means PC Gamer editors will soon be arguing about combat mechanics again
Image of Ronaldo from Fatal Fury: City of the Wolves trailer
It doesn't really make sense that soccer star Ronaldo is now a Fatal Fury character, but if you follow the money you can see how it happened