{"id":220182,"date":"2022-11-24T18:10:00","date_gmt":"2022-11-24T15:10:00","guid":{"rendered":"https:\/\/geek.mediadoma.com\/?p=220182"},"modified":"2022-12-04T14:20:12","modified_gmt":"2022-12-04T11:20:12","slug":"forskare-hittar-nytt-windows-utnyttjande-beraettar-av-misstag-foer-hackare-hur-man-anvaender-det","status":"publish","type":"post","link":"https:\/\/geek.mediadoma.com\/sv\/forskare-hittar-nytt-windows-utnyttjande-beraettar-av-misstag-foer-hackare-hur-man-anvaender-det\/","title":{"rendered":"Forskare hittar nytt Windows-utnyttjande, ber\u00e4ttar av misstag f\u00f6r hackare hur man anv\u00e4nder det"},"content":{"rendered":"<p>Microsoft<\/p>\n<p>I juni korrigerade Microsoft en kritiskt klassad s\u00e5rbarhet som heter CVE-2021-1675. Denna s\u00e5rbarhet gjorde det m\u00f6jligt f\u00f6r hackare att ta fj\u00e4rrkontroll \u00f6ver datorer via Print Spooler-systemet \u2013 ganska l\u00e4skiga saker! Tyv\u00e4rr har forskare vid det kinesiska teknikf\u00f6retaget Sangfor sl\u00e4ppt en liknande exploatering som heter <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">PrintNightmare<\/a> efter att ha ber\u00e4ttat f\u00f6r hackare hur man kan dra f\u00f6rdel av en tidigare ouppt\u00e4ckt bugg.<\/p>\n<blockquote>\n<p><strong>Uppdatering, 7\/7\/21 11:29 Eastern:<\/strong> Microsoft driver nu <a href=\"https:\/\/geek.mediadoma.com\/sv\/uppdatering-det-fungerar-inte-uppdatera-din-windows-dator-nu-foer-att-korrigera-saarbarheten-i-printnightmare\/\" title=\"en n\u00f6duppdatering\">en n\u00f6duppdatering<\/a> f\u00f6r att korrigera s\u00e5rbarheten PrintNightmare. Den h\u00e4r uppdateringen str\u00e4cker sig till de flesta versioner av Windows operativsystem, inklusive Windows 7.<\/p>\n<\/blockquote>\n<p>Hur h\u00e4nde det h\u00e4r? Jo, Sangfor f\u00f6rbereder sig f\u00f6r att h\u00e5lla en konferens om Windows skrivarsystem, som alltid har varit s\u00e5rbart f\u00f6r hackare. F\u00f6r att g\u00f6ra folk redo f\u00f6r den h\u00e4r konferensen best\u00e4mde sig Sangfor f\u00f6r att publicera <a href=\"https:\/\/doublepulsar.com\/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">ett Proof of Concept<\/a> (POC) som f\u00f6rklarar hur den nyligen korrigerade CVE-2021-1675 fungerar och alla farliga saker du kan g\u00f6ra med den.<\/p>\n<p>Men dessa forskare lekte inte med CVE-2021-1675. Det visar sig att de hade uppt\u00e4ckt en liknande s\u00e5rbarhet i Windows Print Spooler som heter <a href=\"https:\/\/doublepulsar.com\/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">PrintNightmare<\/a> \u2014 som nu b\u00e4r den smickrande CVE-2021-34527 monikern. Genom att publicera en POC p\u00e5 PrintNightmare l\u00e4rde Sangfor effektivt hackare hur man drar f\u00f6rdel av ett farligt nolldagsfel i Windows-systemet.<\/p>\n<p>PrintNightmare p\u00e5verkar alla versioner av Windows, <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">enligt Microsoft<\/a>. Det \u00e4r en bugg i Windows Print Spooler \u2013 ett komplicerat verktyg som Windows anv\u00e4nder f\u00f6r att bland annat jonglera med utskriftsscheman. Hackare som utnyttjar denna s\u00e5rbarhet f\u00e5r full kontroll \u00f6ver ett system, med kraften att k\u00f6ra godtycklig kod, installera programvara och hantera filer.<\/p>\n<p>I ett inl\u00e4gg fr\u00e5n <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Microsoft Security Response Center<\/a> den 1 juni uppger f\u00f6retaget att hackare m\u00e5ste logga in p\u00e5 en PC innan de k\u00f6r PrintNightmare-exploatet (vilket inneb\u00e4r att f\u00f6retag, bibliotek och andra organisationer med stora n\u00e4tverk kan vara de mest s\u00e5rbara). Microsoft s\u00e4ger att hackare aktivt utnyttjar PrintNightmare f\u00f6r att \u00e4ventyra system, s\u00e5 ber\u00f6rda parter b\u00f6r vidta \u00e5tg\u00e4rder f\u00f6r att <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">mildra problemet<\/a>.<\/p>\n<p>F\u00f6r n\u00e4rvarande \u00e4r dock det enda s\u00e4ttet att f\u00f6rsvara en PC fr\u00e5n PrintNightmare att inaktivera utskriftsfunktioner som Print Spooler. Denna f\u00f6rsiktighets\u00e5tg\u00e4rd kan vara om\u00f6jlig i organisationer d\u00e4r utskriftsn\u00e4tverk \u00e4r en n\u00f6dv\u00e4ndighet, men du kan l\u00e4ra dig hur du tar dessa steg p\u00e5 <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Microsoft Security Response Center<\/a>.<\/p>\n<p>K\u00e4lla: <a href=\"https:\/\/click.linksynergy.com\/deeplink?id=2QzUaswX1as&amp;mid=24542&amp;u1=rg\/91113&amp;murl=https%3A%2F%2Fmsrc.microsoft.com%2Fupdate-guide%2Fvulnerability%2FCVE-2021-34527\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Microsoft<\/a> via <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-shares-mitigations-for-windows-printnightmare-zero-day-bug\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Bleeping Computer<\/a>, <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2021\/07\/02\/new-critical-security-warning-issued-for-all-windows-versions-as-printnightmare-confirmed\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Forbes<\/a><\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">Inspelningsk\u00e4lla:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/www.reviewgeek.com\" class=\"external external_icon\">www.reviewgeek.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I juni korrigerade Microsoft en kritiskt klassad s\u00e5rbarhet som heter CVE-2021-1675. Denna s\u00e5rbarhet gjorde det m\u00f6jligt f\u00f6r hackare att ta fj\u00e4rrkontroll \u00f6ver datorer via Print Spooler-systemet \u2013 ganska l\u00e4skiga saker! Tyv\u00e4rr har forskare vid det kinesiska teknikf\u00f6retaget Sangfor sl\u00e4ppt en liknande exploatering som heter PrintNightmare efter att ha ber\u00e4ttat f\u00f6r hackare hur man kan dra f\u00f6rdel av en tidigare ouppt\u00e4ckt bugg.<\/p>\n","protected":false},"author":1,"featured_media":230601,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[741,730,759],"tags":[],"class_list":["post-220182","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-diverse","category-nyheter","category-sakerhet"],"_links":{"self":[{"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/posts\/220182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/comments?post=220182"}],"version-history":[{"count":0,"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/posts\/220182\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/media\/230601"}],"wp:attachment":[{"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/media?parent=220182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/categories?post=220182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/geek.mediadoma.com\/sv\/wp-json\/wp\/v2\/tags?post=220182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}