This #printnightmare / CVE-2021-1675 is really serious
Just adapted/simplified original POC then:
*From Remote standard user to SYSTEM*
Here on a domain controller, but valid on all systems with RPC to spooler available, remote or local
disable service now (no patch yet)pic.twitter.com/qpUFgPUZyh
-
Show this thread
-
Replying to @gentilkiwi
Disabling spooler service on DC's is somehow controversial if you have published printers in AD ?https://docs.microsoft.com/en-us/windows-server/security/windows-services/security-guidelines-for-disabling-system-services-in-windows-server#print-spooler …
3 replies 1 retweet 8 likes
Replying to @decoder_it @gentilkiwi
getting every pc in organization ransom wared is also controversial though
0 replies
1 retweet
19 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.