If the patch didnt work this is worst vulnerability in a long time. When you enable passwordless sharing you enable guest account that can also printhttps://twitter.com/gentilkiwi/status/1410066827590447108 …
-
Show this thread
Okay- this indeed is starting to look like worst security failure in many years. It happening on ITSEC BIKINI day is perfect Remember- the name bikini was chosen to provoke as it refers to the bikini island. Both today and bikini island have in common that shit went NUCLEAR bad
2:41 AM - 30 Jun 2021
0 replies
0 retweets
15 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Just adapted/simplified original POC then:
*From Remote standard user to SYSTEM*
Here on a domain controller, but valid on all systems with RPC to spooler available, remote or local
disable service now (no patch yet)