Millions of Windows PCs Vulnerable to 20-Year-Old Bug

Advertisement
By Tasneem Akolawala | Updated: 14 July 2016 18:57 IST
Highlights
  • The vulnerability dates back to Windows 95
  • Microsoft's security update comes is for Windows Vista and later
  • Windows XP and earlier versions remain exposed
Millions of Windows PCs Vulnerable to 20-Year-Old Bug

A 20-year-old vulnerability that exists in the Windows Print Spooler process can potentially affect millions of Windows PCs, all the way back to Windows 95. While Microsoft has issued a patch for Windows Vista and later operating systems, earlier versions are still vulnerable.

The critical vulnerability is based on the way Windows machines interact with network printers, and could allow an attacker to gain elevated privileges to execute malicious code at the system level over either a local network or even the Internet.

The Windows Print Spooler manages the process of connecting the laptop/ PC to available network-hosted printers. It automatically downloads necessary drivers immediately, to avoid manual hassle, and this failure to authenticate made it possible for attackers to trickle malicious drivers into the mix.

Researchers from Vectra Networks discovered the critical vulnerability (CVE-2016-3238 and CVE-2016-3239), and claims that this failure to authenticate installation of drivers can allow illegitimate and malicious drivers to be downloaded. Once this happens, the entire network could be compromised. "Not only will that unit be able to infect multiple machines in your network, but it would also be able to re-infect [them] over and over. Finding the root cause might be harder since the printer itself might not be your usual suspect. This situation comes to life because we end up delegating the responsibility of holding the driver safely to the printer, and those devices might not be as secure or impregnable as one would hope," Vectra researcher Nick Beauchesne wrote in a blog post.

Advertisement

Equipped with system-level controls, the malware can spread laterally from one machine across an entire network as well. Vectra added that printers, printer servers, or any network-connected printer into an "internal drive-by exploit kit." Apart from watering hole attacks, the team detailed privilege escalation exploits, a man-in-the-middle attack, and even the ability to infect other devices over the Internet.

Vectra claims that this vulnerability dates back to as far as Windows 95, and Microsoft's new patch, detailed in its Security Bulletin MS16-087, rated the vulnerability as critical for all supported Windows versions, and issued a Security Update for Windows Print Spooler Components for Windows Vista and later versions. If you don't have Windows Update turned on, now is a good time to do so.

Advertisement

Notably, security expert HD Moore informed Ars Technica that the Microsoft security update in fact '"doesn't really close the code-execution hole, but rather it merely adds a warning as part of the update."

The update doesn't work for PCs running on Windows XP and earlier, as Microsoft ended support for these versions years ago. This means that millions of PCs are still vulnerable. As such, the malware threat is more susceptible to public printers, or loosely-protected office networks.

Moore adds, "This is mostly a risk for BYOD laptops within a company, folks using personal laptops on public networks, and corporate networks where the group policy explicitly enables this feature. Convincing someone to add a printer might be tricky, but there may be other ways to drive that behaviour through other network attacks, such as by hijacking HTTP requests and telling the user to do so."
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lenovo Yoga Slim 7i Aura Edition Review: A Premium All-Rounder with a Few Rough Edges
  2. Samsung Galaxy S24 Ultra and Galaxy S24 Price Lowered on Amazon
  3. Nothing Phone 3 Surfaces on Walmart Website Which Reaffirms Its US Launch
  4. Android 16 QPR1 Beta 2 Update Brings New Launch Animation for Gemini
  1. NASA Chandra Spots Distant X-Ray Jet; Telescope Faces Major Budget Cuts
  2. JWST Reveals Pluto’s Haze Cools Atmosphere, Paints Charon’s Poles Red
  3. Earth’s Oceans Enter Danger Zone Due to Rising Acidification, New Study Warns
  4. Samsung Galaxy S24 Ultra, Galaxy S24 Price Lowered on Amazon With Discounts, Cashback Offers
  5. Maryade Prashne Now Streaming on SunNXT: Everything You Need to Know
  6. Good Wife OTT Release: When and Where to Watch Tamil Legal Drama Online?
  7. Android 16 QPR1 Beta 2 Update for Pixel Reportedly Brings New Launch Animation for Gemini Overlay
  8. Jinn - The Pet OTT Release Date: When and Where to Where to Watch Tamil Horror-Comedy Online?
  9. DD Next Level Now Streaming: Know Where to Watch This Tamil Horror-Comedy
  10. Nothing Phone 3 Listed on Walmart Website, Reaffirming Its Launch in the US
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.