愛污传媒

Skip to main content

Microsoft's Windows security flaw is a big deal. Here's what you can do about it

Microsoft is urging Windows users to immediately install an update after security researchers found a serious vulnerability in the operating system. (CNN)
Microsoft is urging Windows users to immediately install an update after security researchers found a serious vulnerability in the operating system. (CNN)
Share

Microsoft's latest security vulnerability could have a lingering impact both on consumers and businesses at a time when many around the world are already on high alert for .

Researchers at security firm Sangfor recently , called PrintNightmare, that could allow hackers to remotely gain access to the operating system and install programs, view and delete data or even create new user accounts with full user rights. The firm accidentally leaked instructions on how the flaw could be exploited by hackers, exacerbating the need for Windows users to update their systems immediately.

Here's what you should know about the issue and how to address it:

HAS MY WINDOWS DEVICE BEEN IMPACTED?

Microsoft is all Windows users to that affects the Windows Print Spooler service, which allows multiple users to access a printer. The company has already rolled out fixes for Windows 10, Windows 8, Windows 7 and some server versions. Microsoft ended support for Windows 7 last year, so the decision to push an update to that software highlights the severity of the PrintNightmare flaw.

Although many Windows users don't have remote access capabilities on their home computers, business computers or people working remotely and connecting back to the office could be most affected, according to Michela Menting, a cybersecurity expert at ABI Research.

HOW BIG A DEAL IS THIS?

Windows 10 runs on about about 1.3 billion devices worldwide, according to market research firm CCS Insight, so the magnitude of the vulnerability's reach is massive. "This is a big deal because Windows 10 is the most popular desktop OS out there with over 75% market share," Menting said.

Because Windows 10 is used by desktop computers as well as some servers, it could potentially enable hackers to infiltrate a network "very quickly" and get in "practically anywhere to find the most lucrative databases and systems," Menting said.

Once Sangfor shared a proof-of-concept exploit code on the Microsoft-owned code hosting platform Github, it was copied by users before it was deleted.

HOW TO DOWNLOAD THE PATCH

Windows users can visit the Settings page, then select the Update & Security option, followed by Windows Update, or else to download the new software.

However, one researcher on Twitter how isn't entirely effective, leaving room for potential actors to still exploit the vulnerability. After this story published, a Microsoft spokesperson said the company is "not aware of any bypasses to the update" but continues to investigate the matter.

Menting said a buggy patch is in many ways like "years in cybercrime time," adding it's "highly likely" ransomware attacks or data theft could occur as a result. "There is no doubt that not every company will have updated their OS before attackers get in," she said.

THE BIG TAKEAWAY

Still, the incident serves as a reminder for both businesses and consumers to routinely update any kind of software to ensure impacted systems aren't left exposed. For anyone who believes they could be at risk to a vulnerability or isn't sure, Menting suggested disabling impacted functions until a company rolls out an official fix.

CTVNews.ca Top Stories

The president and CEO of New Brunswick-based Covered Bridge Potato Chips is taking an 'extended leave of absence' after being charged with domestic violence this past weekend.

A memorial is growing outside a Walmart in Halifax after a 19-year-old employee was found dead inside an oven in the store Saturday night.

A search has started at Prairie Green Landfill for the remains of two victims of a serial killer.

He is a familiar face to residents of a neighbourhood just west of Roncesvalles Avenue.

Canada's discount airline is suspending operations to and from Saskatoon.

A new report suggests that Canadians' exposure to a radioactive gas is increasing, putting millions of people at a higher risk of developing lung cancer.

Local Spotlight

He is a familiar face to residents of a neighbourhood just west of Roncesvalles Avenue.

A meteor lit up our region's sky last night 鈥 with a large fireball shooting across the horizon over Lake Erie at around 7:00 p.m.

Residents of Ottawa's Rideauview neighbourhood say an aggressive wild turkey has become a problem.

A man who lost his life while trying to rescue people from floodwaters, and a 13-year-old boy who saved his family from a dog attack, are among the Nova Scotians who received a medal for bravery Tuesday.

A newly minted Winnipegger is hoping a world record attempt will help bring awareness for the need for more pump track facilities in the city.

A Springfield, Ont. man is being hailed a 'hero' after running into his burning home to save his two infant children.

Hortense Anglin was the oldest graduate to make her way across the platform at York University's Fall Convocation ceremony this week. At the age of 87, she graduated with an Honours degree in Religious Studies.

Looking for a scare with good intentions this Halloween season? The ghosts and ghouls of Eganville, Ont. invite families to tour the Haunted Walk at Lekbor Manor.

The image of a sleepy Saskatchewan small town with 'not a lot going on' is a well-known anecdote. However, one Saskatchewan company is hoping to change that 鈥 and allow communities both on and off the beaten path to share their stories and advertise what they have to offer.