Millions of Windows PCs Vulnerable to 20-Year-Old Bug

Advertisement
By Tasneem Akolawala | Updated: 14 July 2016 18:57 IST
Highlights
  • The vulnerability dates back to Windows 95
  • Microsoft's security update comes is for Windows Vista and later
  • Windows XP and earlier versions remain exposed

A 20-year-old vulnerability that exists in the Windows Print Spooler process can potentially affect millions of Windows PCs, all the way back to Windows 95. While Microsoft has issued a patch for Windows Vista and later operating systems, earlier versions are still vulnerable.

The critical vulnerability is based on the way Windows machines interact with network printers, and could allow an attacker to gain elevated privileges to execute malicious code at the system level over either a local network or even the Internet.

Advertisement

The Windows Print Spooler manages the process of connecting the laptop/ PC to available network-hosted printers. It automatically downloads necessary drivers immediately, to avoid manual hassle, and this failure to authenticate made it possible for attackers to trickle malicious drivers into the mix.

Researchers from Vectra Networks discovered the critical vulnerability (CVE-2016-3238 and CVE-2016-3239), and claims that this failure to authenticate installation of drivers can allow illegitimate and malicious drivers to be downloaded. Once this happens, the entire network could be compromised. "Not only will that unit be able to infect multiple machines in your network, but it would also be able to re-infect [them] over and over. Finding the root cause might be harder since the printer itself might not be your usual suspect. This situation comes to life because we end up delegating the responsibility of holding the driver safely to the printer, and those devices might not be as secure or impregnable as one would hope," Vectra researcher Nick Beauchesne wrote in a blog post.

Advertisement

Equipped with system-level controls, the malware can spread laterally from one machine across an entire network as well. Vectra added that printers, printer servers, or any network-connected printer into an "internal drive-by exploit kit." Apart from watering hole attacks, the team detailed privilege escalation exploits, a man-in-the-middle attack, and even the ability to infect other devices over the Internet.

Vectra claims that this vulnerability dates back to as far as Windows 95, and Microsoft's new patch, detailed in its Security Bulletin MS16-087, rated the vulnerability as critical for all supported Windows versions, and issued a Security Update for Windows Print Spooler Components for Windows Vista and later versions. If you don't have Windows Update turned on, now is a good time to do so.

Advertisement

Notably, security expert HD Moore informed Ars Technica that the Microsoft security update in fact '"doesn't really close the code-execution hole, but rather it merely adds a warning as part of the update."

The update doesn't work for PCs running on Windows XP and earlier, as Microsoft ended support for these versions years ago. This means that millions of PCs are still vulnerable. As such, the malware threat is more susceptible to public printers, or loosely-protected office networks.

Moore adds, "This is mostly a risk for BYOD laptops within a company, folks using personal laptops on public networks, and corporate networks where the group policy explicitly enables this feature. Convincing someone to add a printer might be tricky, but there may be other ways to drive that behaviour through other network attacks, such as by hijacking HTTP requests and telling the user to do so."
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy A57 5G: Smart Choice That Redefines Mid-Range Value
  2. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  3. Vivo T5 Pro 5G Confirmed to Launch in India Soon With These Features
  4. Google Pixel 10 Users Can Now Play Steam Games Offline via GameNative
  5. These Four Motorola Phones Are Now Eligible to Get Android 17 Beta Updates
  6. Here's When the Oppo K15 Pro Series Could Be Launched in India
  1. Microsoft Releases New AI Models That Can Generate Images, Audio and Transcribe Text
  2. Redmi K Pad 2, New Redmi Laptops Tipped to Launch Alongside Redmi K90 Ultra
  3. Google Pixel 10 Users Can Now Play Steam Games Offline via GameNative 0.9.0
  4. Circle Unveils cirBTC Token to Expand Bitcoin’s Role in DeFi Ecosystem
  5. Honor 600 Series Could Launch Soon as Company Starts Teasing Debut of a New Phone
  6. Microsoft AI Chief Wants to Deliver State-of-the-Art AI Models by 2027: Report
  7. Infinix GT 50 Pro Leak Shows Design, Cooling, Gaming Features Ahead of Anticipated Launch
  8. Samsung Galaxy Z Fold 8, Galaxy Z Flip 8 to Stick With Older M13 OLED Panels: Report
  9. Crypto Hack Losses Drop to $168.6 Million in Q1 2026 Despite Ongoing Risks
  10. Google Vids Will Now Let All Users Generate Veo 3.1 AI Videos for Free, New Features Added
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.