Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft’s fix for PrintNightmare vulnerability is reportedly ineffective

Microsoft’s fix for PrintNightmare vulnerability is reportedly ineffective

kip@winbeta.org kip@winbeta.org
July 8, 2021
2 min read

Microsoft released emergency fixes earlier this week to address the “PrintNightmare” remote code execution exploit affecting all versions of Windows, but it looks like the out-of-band updates still leave some holes in the wall. Since Microsoft published the fixes, several security researchers have shown that it was still possible to exploit the vulnerability on patched systems and servers (via Bleeping Computer).

The PrintNightmare security flaw is a remote code execution vulnerability affecting the Windows Print Spooler service, a component that manages the printing process on Windows PCs inside local networks. Yesterday Benjamin Delpy, a Windows security expert and a developer of the network utility Mimikatz, showed a remote code execution (RCE) and local privilege escalation (LPE) exploit on a patched Windows Server 2019 with the Point and Print technology enabled.

Dealing with strings & filenames is hard😉
New function in #mimikatz 🥝to normalize filenames (bypassing checks by using UNC instead of \servershare format)

So a RCE (and LPE) with #printnightmare on a fully patched server, with Point & Print enabled

> https://t.co/Wzb5GAfWfd pic.twitter.com/HTDf004N7r

— 🥝 Benjamin Delpy (@gentilkiwi) July 7, 2021

Point and Print is an old Microsoft technology that allows Windows users to connect to a remote printer while downloading all necessary files and configuration information from the print server. “Point and Print is not directly related to this vulnerability, but the technology weakens the local security posture in such a way that exploitation will be possible,” Microsoft acknowledged in its Security Advisory for PrintNightmare.

Along with the release of its emergency fixes on Tuesday, Microsoft also provided IT admins a new way to restrict the installation of new printer drivers for non-administrators. However, the Point and Print technology, which can be disallowed for non-administrators is apparently still problematic and should require more investigation work from Microsoft. Speaking with Bleeping Computer, Microsoft said that “We’re aware of claims and are investigating, but at this time we are not aware of any bypasses.”

Share This Post:

Share this article:
Tags:
Security Windows 10
Previous Article Skype starts testing animated background for video calls – onmsft.com Next Article Microsoft Lists is getting support for custom templates this month – onmsft.com

Related Articles

Meta Shifts Content Moderation to AI, Cuts Third-Party Review

Meta Shifts Content Moderation to AI, Cuts Third-Party Review

March 19, 2026

Rivian delays 2027 profitability target due to rising autonomy costs

March 19, 2026
Viral story claims ChatGPT cured a dog’s cancer, but experts say AI only assisted research while doctors handled treatment and testing.

Dog Cancer “Cure” Claim Overstates ChatGPT’s Role

March 19, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Meta Shifts Content Moderation to AI, Cuts Third-Party Review
  • Rivian delays 2027 profitability target due to rising autonomy costs
  • Dog Cancer “Cure” Claim Overstates ChatGPT’s Role
  • NVIDIA DLSS 5 Trailer Gets Massive Dislikes on YouTube
  • Meta launches Creator Fast Track to pay TikTok and YouTube creators on Facebook

Recent Comments

No comments to show.
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Meta Shifts Content Moderation to AI, Cuts Third-Party Review
  • Rivian delays 2027 profitability target due to rising autonomy costs
  • Dog Cancer “Cure” Claim Overstates ChatGPT’s Role
  • NVIDIA DLSS 5 Trailer Gets Massive Dislikes on YouTube
  • Meta launches Creator Fast Track to pay TikTok and YouTube creators on Facebook

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy