Updated News Around the World

Microsoft Windows users alert! New flaw lets hackers control system functions

Microsoft has discovered a new vulnerability in the Windows operating system’s Print Spooler service. This new vulnerability can be misused by cybercriminals in order to take control of one’s system operations.

In a recent statement, the company stated, “Microsoft is aware of and investigating a remote code execution vulnerability that affects Windows Print Spooler and has assigned CVE-2021-34527 to this vulnerability. This is an evolving situation and we will update the CVE as more information is available.”

Microsoft claims that a remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations.

With the use of this vulnerability in the Windows operating system, cybercriminals could run arbitrary code with System privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft has confirmed that all versions of Windows contain the vulnerable code and are vulnerable. However, there are certain conditions that need to be met on the system to enable exploitation.

In order to prevent your system from being victim to cybercriminals who plan to use this new vulnerability, Microsoft claims users should apply the security updates released on June 8, 2021.

Further, to work around the vulnerability, users can disable Print Spooler. However, disabling the Print Spooler service disables the ability to print both locally and remotely.

The second option is to disable inbound remote printing through Group Policy. This can be done by going to Computer Configuration / Administrative Templates / Printers and then disable the “Allow Print Spooler to accept client connections:” policy to block remote attacks.

This policy will block the remote attack vector by preventing inbound remote printing operations. The system will no longer function as a print server, but local printing to a directly attached device will still be possible.

Subscribe to Mint Newsletters

* Enter a valid email

* Thank you for subscribing to our newsletter.

Never miss a story! Stay connected and informed with Mint.
Download
our App Now!!

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! NewsUpdate is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.