金牌投注娱乐城官网

各校内师生:

PrintSpooler是Windows系统中管理打印相关事务的金牌投注娱乐城,用于管理所有本地和金牌投注打印队列并控制所有打印工作。Windows系统默认开启PrintSpooler金牌投注娱乐城,普通用户可以利用此漏洞提升至SYSTEM管理权限。在域环境下,域用户可远程利用该漏洞以SYSTEM权限在域控制器上执行任意代码,从而获得整个域的控制权。

一、影响范围

Windows Server 2012 R2 (ServerCore installation)

Windows Server 2012 R2

Windows Server 2012 (Server Core installation)

Windows Server 2012

Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows RT 8.1

Windows 8.1 for x64-based systems

Windows 8.1 for 32-bit systems

Windows 7 for x64-based Systems Service Pack 1

Windows 7 for 32-bit Systems Service Pack 1

Windows Server 2016 (Server Core installation)

Windows Server 2016

Windows 10 Version 1607 for x64-based Systems

Windows 10 Version 1607 for 32-bit Systems

Windows 10 for x64-based Systems

Windows 10 for 32-bit Systems

Windows Server, version 20H2 (Server Core Installation)

Windows 10 Version 20H2 for ARM64-based Systems

Windows 10 Version 20H2 for 32-bit Systems

Windows 10 Version 20H2 for x64-based Systems

Windows Server, version 2004 (Server Core installation)

Windows 10 Version 2004 for x64-based Systems

Windows 10 Version 2004 for ARM64-based Systems

Windows 10 Version 2004 for 32-bit Systems

Windows 10 Version 21H1 for 32-bit Systems

Windows 10 Version 21H1 for ARM64-based Systems

Windows 10 Version 21H1 for x64-based Systems

Windows Server, version 1909 (Server Core installation)

Windows 10 Version 1909 for ARM64-based Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for 32-bit Systems

Windows Server 2019 (Server Core installation)

Windows Server 2019

Windows 10 Version 1809 for ARM64-based Systems

Windows 10 Version 1809 for x64-based Systems

Windows 10 Version 1809 for 32-bit Systems

二、漏洞防护

目前微软官方已针对支持的系统版本发布了修复以上漏洞的安全补丁,强烈建议受影响用户尽快安装补丁进行防护,下载链接:

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-1675

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-34527

本次补丁安装需要一定前置更新,详情请参考:https://support.microsoft.com/zh-cn/topic/july-6-2021-kb5004945-os-builds-19041-1083-19042-1083-and-19043-1083-out-of-band-44b34928-0a71-4473-aa22-ecf3b83eed0e

:由于金牌投注问题、计算机环境问题等原因,Windows Update的补丁更新可能出现失败。用户在安装补丁后,应及时检查补丁是否成功更新。

针对未成功安装的更新,可点击更新名称跳转到微软官方下载页面,建议用户点击该页面上的链接,转到“Microsoft更新目录”网站下载独立程序包并安装。

2.1临时防护措施

一、用户可通过停止并禁用Print Spooler金牌投注娱乐城对以上漏洞进行缓解:

进入任务管理器,选择“金牌投注娱乐城”->“打开金牌投注娱乐城”->“选择Print Spooler”->“右键属性”。

金牌投注娱乐城官网金牌投注娱乐城官网

启动类型“选择禁用”,并点击“停止”,关闭金牌投注娱乐城,点击“应用”和“确定”,使配置生效。

金牌投注娱乐城官网

注:停用此金牌投注娱乐城将导致打印功能失效。

二、通过组策略禁用入站远程打印:

运行组策略编辑器(Win+R,输入gpedit.msc,打开组策略编辑器),依次浏览到:计算机配置/管理模板/打印机:禁用“允许打印后台处理程序接受客户端连接:”策略以阻止远程攻击。

注:此策略将通过阻止入站远程打印操作来阻止远程攻击。该系统将不再用作打印金牌投注娱乐城器,但仍然可以本地打印到直接连接的设备。

金牌投注娱乐城联系电话:0472-5288017/13500620202

金牌投注中心

2021年9月7日

上一篇:关于“HTTP协议栈远程代码执行漏洞”金牌投注安全预警通报的通知

下一篇:关于“微软Windows操作系统存在TCP/IP高危漏洞”金牌投注安全预警通报的通知

关闭