Skip to main content

PrintNightmare isn’t over, as Windows is hit with another printing vulnerability

The vulnerabilities in the Windows Print Spooler service just won’t end for Microsoft. Despite a recent patch, a cybersecurity researcher has managed to exploit a new bug in the spooler — showing how someone with bad intent can gain administrative privileges in Windows by using a custom print server.

The new vulnerability works only in a specific situation but is still concerning since it’s not patched. Security researcher Benjamin Delpy showcased the inner workings of the vulnerability on his Twitter. This involves using a specific custom print server to install a specially created print driver that can run at the system-privilege level. This can allow non-admin users to open a command prompt with elevated privileges. You can see this in action in this video, as tested by Bleeping Computer, which first reported on the vulnerability.

Demonstration of remote PrintNightmare driver open a SYSTEM command prompt

Since the vulnerability is not patched, the easiest way to prevent it would be to disable Windows Print Spooler entirely. However, an advisory posted online showcases other methods. These are more complex and involve blocking remote traffic and restricting Point and Print functionality via the Group Policy editor. This makes it so non-admin users can only install print drivers from an approved list, but permitted print servers still can be injected with bad drivers.

Recommended Videos

It doesn’t seem like there’s going to be an end to PrintNightmare vulnerabilities anytime soon. Microsoft already fixed the initial PrintNightmare issue with a rare out-of-band patch, but since then security researchers have been digging into Microsoft’s fix and raising new concerns. On July 16, researchers demonstrated that someone with local (physical) access to a PC can use the Print Spooler to install programs and view, change, or delete data under a specific scenario.

This would be the third big issue reported by researchers, and there could be more on the way soon. The DefCon and Black Hat conferences are coming up. Usually, that’s where issues like this one are discussed. DefCon is the largest underground conference where hackers, corporate IT professionals, and government agencies aim to expand their knowledge and skill set in the world of hacking.

Arif Bacchus
Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
Intel Battlemage is almost here, but the wait isn’t over
Intel Arc A770 GPU installed in a test bench.

After weeks of rumors, it's finally a fact: Intel Arc Battlemage is on the imminent horizon, and the company is set to announce its next-gen GPUs on December 3. However, according to leaks, we're not getting the full scope of Intel Battlemage just yet. In fact, it may be a long time before we see Battlemage rank among the best graphics cards.

It's been a quiet year for Intel's discrete graphics department, but the last few weeks have been filled with leaks, and now, Intel itself confirms that we're getting some sort of an announcement tomorrow. It's unclear what exactly is being announced, other than the fact that it's Battlemage.

Read more
Windows 11 remains the driver of growth in PCs, not AI
The Surface Laptop shown in front of a Copilot+ sign.

There's been a lot of talk about AI PCs this year, but has it actually delivered on its promise? A new analysis from TrendForce says the significant boost in laptop sales in 2024 has more to do with Windows 11 updates than it does with fancy new AI features.

"The impact of AI-integrated notebooks on the overall market remains limited for now," the report states. "However, AI features are expected to naturally integrate into notebook specifications as brands gradually incorporate them, resulting in a steady rise in the penetration rates of AI notebooks."

Read more
Windows 11 vs. Windows 10: Is it finally time to update?
Microsoft Surface Laptop 2 sitting on a table.

Windows 11 is the newest version of Windows, and it's one of the best Windows versions ever released. It draws on its predecessors, like Windows 10, but today it's very much its own operating system, with a unique look, advanced features, and the most secure and stable platform for modern Windows application.

If you've been holding out on upgrading, or aren't running the latest version, we have everything you need to know about the most recent version of Windows 11.
Windows 11 2024 update (24H2)
The latest version of Windows 11, is the 2024 update known as 24H2. It initially rolled out to Windows Insiders in February 2024, but has since been released to the wider Windows user base starting October 1. It introduced a number of new and enhanced features to Windows, improving its fundamentals, as well as adding new capabilities, especially those running it on Copilot+ PCs and laptops.

Read more