If the patch didnt work this is worst vulnerability in a long time. When you enable passwordless sharing you enable guest account that can also printhttps://twitter.com/gentilkiwi/status/1410066827590447108 …
-
Show this thread
also very likely this is also is a windows sandbox escape- there is this nasty printer driver that make printing on host possible. Last i checked i could also print exe files on the host in locations guest could write.
0 replies
1 retweet
14 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Just adapted/simplified original POC then:
*From Remote standard user to SYSTEM*
Here on a domain controller, but valid on all systems with RPC to spooler available, remote or local
disable service now (no patch yet)