Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Surface
  • Reviews
  • Xbox
  • Gaming
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Surface
  • Reviews
  • Xbox
  • Gaming
  1. Home
  2. News
  3. Microsoft’s fix for PrintNightmare vulnerability is reportedly ineffective

Microsoft’s fix for PrintNightmare vulnerability is reportedly ineffective

kip@winbeta.org kip@winbeta.org
July 8, 2021
2 min read

Microsoft released emergency fixes earlier this week to address the “PrintNightmare” remote code execution exploit affecting all versions of Windows, but it looks like the out-of-band updates still leave some holes in the wall. Since Microsoft published the fixes, several security researchers have shown that it was still possible to exploit the vulnerability on patched systems and servers (via Bleeping Computer).

The PrintNightmare security flaw is a remote code execution vulnerability affecting the Windows Print Spooler service, a component that manages the printing process on Windows PCs inside local networks. Yesterday Benjamin Delpy, a Windows security expert and a developer of the network utility Mimikatz, showed a remote code execution (RCE) and local privilege escalation (LPE) exploit on a patched Windows Server 2019 with the Point and Print technology enabled.

Dealing with strings & filenames is hard😉
New function in #mimikatz 🥝to normalize filenames (bypassing checks by using UNC instead of \servershare format)

So a RCE (and LPE) with #printnightmare on a fully patched server, with Point & Print enabled

> https://t.co/Wzb5GAfWfd pic.twitter.com/HTDf004N7r

— 🥝 Benjamin Delpy (@gentilkiwi) July 7, 2021

Point and Print is an old Microsoft technology that allows Windows users to connect to a remote printer while downloading all necessary files and configuration information from the print server. “Point and Print is not directly related to this vulnerability, but the technology weakens the local security posture in such a way that exploitation will be possible,” Microsoft acknowledged in its Security Advisory for PrintNightmare.

Along with the release of its emergency fixes on Tuesday, Microsoft also provided IT admins a new way to restrict the installation of new printer drivers for non-administrators. However, the Point and Print technology, which can be disallowed for non-administrators is apparently still problematic and should require more investigation work from Microsoft. Speaking with Bleeping Computer, Microsoft said that “We’re aware of claims and are investigating, but at this time we are not aware of any bypasses.”

Share This Post:

Share this article:
Tags:
Security Windows 10
Previous Article Skype starts testing animated background for video calls – onmsft.com Next Article Microsoft Lists is getting support for custom templates this month – onmsft.com

Related Articles

Gemini in Chrome side panel showing PDF summary options alongside an open document

Chrome could soon automatically summarize PDFs with Gemini

April 8, 2026

Snapdragon X2 Elite Gaming Shows Real Progress but Still Falls Short for Serious Players

April 8, 2026

ASUS Says No New Motherboards Needed for Intel Core Ultra 200S Plus

April 8, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome could soon automatically summarize PDFs with Gemini
  • Snapdragon X2 Elite Gaming Shows Real Progress but Still Falls Short for Serious Players
  • ASUS Says No New Motherboards Needed for Intel Core Ultra 200S Plus
  • Google is Killing Chrome’s Link Preview Feature from Desktop
  • ASUS Snapdragon X2 Laptops Get Sudden Price Increase After Reviews

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome could soon automatically summarize PDFs with Gemini
  • Snapdragon X2 Elite Gaming Shows Real Progress but Still Falls Short for Serious Players
  • ASUS Says No New Motherboards Needed for Intel Core Ultra 200S Plus
  • Google is Killing Chrome's Link Preview Feature from Desktop
  • ASUS Snapdragon X2 Laptops Get Sudden Price Increase After Reviews

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy