1. XenForo 1.5.14 中文版——支持中文搜索!现已发布!查看详情
  2. Xenforo 爱好者讨论群:215909318 XenForo专区

科技 零日漏洞PrintNightmare曝光:可在Windows后台执行远程代码

Discussion in '新闻聚焦' started by 漂亮的石头, 2021-07-01.

  1. 漂亮的石头

    漂亮的石头 版主 Staff Member

    Joined:
    2012-02-10
    Messages:
    488,439
    Likes Received:
    48
    中国安全公司深信服(Sangfor)近日发现了名为 PrintNightmare的零日漏洞,允许黑客在补丁完善的 Windows Print Spooler 设备上获得完整的远程代码执行能力,该公司还发布了概念证明代码。

    [​IMG]

    [​IMG]

    [​IMG]

    在 6 月补丁星期二活动日中,微软发布的安全累积更新中修复了一个类似的 Print Spooler 漏洞。但是对于已经打过补丁的 Windows Server 2019 设备,PrintNightmare 漏洞依然有效,并允许攻击者远程执行代码。​

    根据概念证明代码显示,黑客只需要一些(甚至是低权限)的网络凭证就可以利用该漏洞进行远程执行,而且这些凭证在暗网上只需要 3 美元就能买到。这意味着企业网络又极易受到(尤其是勒索软件)的攻击,安全研究人员建议企业禁用其 Windows Print Spoolers。​

    影响版本


    Windows Server 2019 (Server Core installation)​

    Windows Server 2019​

    Windows Server 2016 (Server Core installation)​

    Windows Server 2016​

    Windows Server 2012 R2 (Server Core installation)​

    Windows Server 2012 R2​

    Windows Server 2012 (Server Core installation)​

    Windows Server 2012​

    Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)​

    Windows Server 2008 R2 for x64-based Systems Service Pack 1​

    Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)​

    Windows Server 2008 for x64-based Systems Service Pack 2​

    Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)​

    Windows Server 2008 for 32-bit Systems Service Pack 2​

    Windows Server, version 2004 (Server Core installation)​

    Windows RT 8.1​

    Windows 8.1 for x64-based systems​

    Windows 8.1 for 32-bit systems​

    Windows 7 for x64-based Systems Service Pack 1​

    Windows 7 for 32-bit Systems Service Pack 1​

    Windows 10 Version 1607 for x64-based Systems​

    Windows 10 Version 1607 for 32-bit Systems​

    Windows 10 for x64-based Systems​

    Windows 10 for 32-bit Systems​

    Windows Server, version 20H2 (Server Core Installation)​

    Windows 10 Version 20H2 for ARM64-based Systems​

    Windows 10 Version 20H2 for 32-bit Systems​

    Windows 10 Version 20H2 for x64-based Systems​

    Windows 10 Version 2004 for x64-based Systems​

    Windows 10 Version 2004 for ARM64-based Systems​

    Windows 10 Version 2004 for 32-bit Systems​

    Windows 10 Version 21H1 for 32-bit Systems​

    Windows 10 Version 21H1 for ARM64-based Systems​

    Windows 10 Version 21H1 for x64-based Systems​

    Windows 10 Version 1909 for ARM64-based Systems​

    Windows 10 Version 1909 for x64-based Systems​

    Windows 10 Version 1909 for 32-bit Systems​

    Windows 10 Version 1809 for ARM64-based Systems​

    Windows 10 Version 1809 for x64-based Systems​

    Windows 10 Version 1809 for 32-bit Systems​
     
Loading...