Re: Looking for a sample of the Microsoft zero day print nightmare

2021-07-11 Thread Kevin A. McGrail
On 7/3/2021 1:44 PM, Kenneth Porter wrote: On 7/2/2021 6:39 PM, Kevin A. McGrail wrote: Anyone know if this is delivered via email? I'm trying to make sure I block the payload if it is. I found a copy of the repo and see that it works by adding an evil printer driver to the remote server ove

Re: Looking for a sample of the Microsoft zero day print nightmare

2021-07-08 Thread Jared Hall
Kenneth Porter wrote: I found a copy of the repo and see that it works by adding an evil printer driver to the remote server over an IP connection. So email is a vector if you allow executable attachments (including scripts). Yes.  Local Privilege Elevation then Remote Command Execution.  Th

Re: Looking for a sample of the Microsoft zero day print nightmare

2021-07-03 Thread Kenneth Porter
On 7/2/2021 6:39 PM, Kevin A. McGrail wrote: Anyone know if this is delivered via email? I'm trying to make sure I block the payload if it is. I found a copy of the repo and see that it works by adding an evil printer driver to the remote server over an IP connection. So email is a vector if

Looking for a sample of the Microsoft zero day print nightmare

2021-07-02 Thread Kevin A. McGrail
https://www.bleepingcomputer.com/news/security/microsoft-shares-mitigations-for-windows-printnightmare-zero-day-bug/ Anyone know if this is delivered via email? I'm trying to make sure I block the payload if it is. Would appreciate anyone reaching out to me off or on list. Regards, KAM