HomeSecurityCISA: Attackers exploit flaw in Windows Print Spooler

CISA: Attackers exploit flaw in Windows Print Spooler

According to an alert from the Cybersecurity and Infrastructure Security Administration (CISA), three new security flaws are being actively exploited by malicious users , including a local privilege escalation bug in the Windows Print Spooler .

See also: Fix this critical Windows RPC error immediately

error

This is a high-severity bug (CVE-2022-22718), affecting all versions of Windows , and was fixed as part of the February 2022 Patch Tuesday, according to Microsoft.

The only information that has been made known by Microsoft regarding this bug is that threat actors can exploit it locally in low-sophistication attacks without requiring user interaction.

This isn't the only bug in Windows Print Spooler that the company has patched. Over the past 12 months, several bugs have been discovered and fixed, including the critical PrintNightmare.

After technical details and a POC for PrintNightmare were leaked, CISA warned administrators to disable the Windows Print Spooler service on domain controllers and systems not used for printing to block potential inbound attacks.

See also: Facebook News Feed bug introduces misinformation into users' feeds

Windows Print Spooler

Last week, CISA added another privilege escalation bug in the Windows Common Log File System driver program to its list of actively exploited flaws, which was reported by CrowdStrike and the US National Security Agency (NSA) and fixed by Microsoft on this month's Patch Tuesday.

According to a binding November operational directive (BOD 22-01), all Federal Civilian Executive Branch Agencies (FCEB) must protect their systems from security flaws added to CISA.

CISA has given agencies three weeks, until May 10, to patch the now-active CVE-2022-22718 vulnerability and block ongoing exploitation attempts.

See also: CISA: Fix the Sophos firewall bug

Although this guidance only applies to U.S. federal organizations, CISA also urges all U.S. organizations to fix this privilege error to prevent privilege escalation attempts on their Windows systems.

Since the issuance of the binding BOD 22-01 directive, CISA has added hundreds of security flaws to the list of actively exploited bugs, prompting US federal agencies to patch them as soon as possible to prevent breaches.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS