Microsoft’s Windows security hole is a big deal. Here’s what you can do about it
Microsoft’s latest security vulnerability could have a lingering impact on both consumers and businesses at a time when many people around the world are already on high alert for disruptive cyber attacks.
Researchers from the security company Sangfor recently discovered a vulnerability in Windows, called PrintNightmare, which could allow hackers to remotely access the operating system and install programs, view and delete data or even create new user accounts with full user rights . The company accidental leakage of instructions on how the vulnerability could be exploited by hackers, exacerbating the need for Windows users to update their systems immediately.
Here’s what you need to know about the problem and how to fix it:
HAS MY WINDOWS DEVICE HAD AN IMPACT?
Microsoft is urging all Windows users to install an update that affects the Windows Print Spooler service, which allows multiple users to access a printer. The company has already deployed fixes for Windows 10, Windows 8, Windows 7, and some server versions. Microsoft ended support for Windows 7 last year, so the decision to push an update for this software highlights the severity of the PrintNightmare flaw.
Although many Windows users do not have remote access capabilities on their personal computers, work computers or people working remotely and logging in to the office could be the most affected, according to Michela Menting, cybersecurity expert at ABI Research.
HOW MUCH IS IT?
According to market research firm CCS Insight, Windows 10 runs on approximately 1.3 billion devices worldwide. The breadth of the scope of the vulnerability is therefore enormous. âThis is a big deal because Windows 10 is the most popular desktop operating system with over 75% market share,â Menting said.
Since Windows 10 is used by desktop computers as well as some servers, it could potentially allow hackers to infiltrate a network “very quickly” and enter “virtually anywhere to find databases and the most lucrative systems, âMenting said.
After Sangfor shared a proof of concept exploit code on Microsoft-owned code hosting platform Github, it was copied by users before being deleted.
HOW TO DOWNLOAD THE PATCH
Windows users can visit the Settings page, then select Update & Security, followed by Windows Update, or visit Microsoft’s website to download new software.
However, a researcher on Twitter show how the emergency update is not fully effective, leaving room for potential actors to continue exploiting the vulnerability. After the story was published, a Microsoft spokesperson said the company “was not aware of any circumvention of the update” but was continuing to investigate the matter.
Menting said a bug fix is ââin many ways like “years in the time of cybercrime,” adding that it is “very likely” that ransomware attacks or data theft could occur as a result. “There is no doubt that not all companies will have updated their operating system before attackers enter,” she said.
THE BIG TO TAKE AWAY
Still, the incident reminds businesses and consumers to regularly update any type of software to ensure affected systems do not remain exposed. For anyone who thinks or isn’t sure they might be exposed to a vulnerability, Menting suggested disabling the impacted features until a company rolls out an official patch.
Comments are closed.