Â鶹´«Ã½

Skip to main content

Microsoft's Windows security flaw is a big deal. Here's what you can do about it

Microsoft is urging Windows users to immediately install an update after security researchers found a serious vulnerability in the operating system. (CNN)
Microsoft is urging Windows users to immediately install an update after security researchers found a serious vulnerability in the operating system. (CNN)
Share

Microsoft's latest security vulnerability could have a lingering impact both on consumers and businesses at a time when many around the world are already on high alert for .

Researchers at security firm Sangfor recently , called PrintNightmare, that could allow hackers to remotely gain access to the operating system and install programs, view and delete data or even create new user accounts with full user rights. The firm accidentally leaked instructions on how the flaw could be exploited by hackers, exacerbating the need for Windows users to update their systems immediately.

Here's what you should know about the issue and how to address it:

HAS MY WINDOWS DEVICE BEEN IMPACTED?

Microsoft is all Windows users to that affects the Windows Print Spooler service, which allows multiple users to access a printer. The company has already rolled out fixes for Windows 10, Windows 8, Windows 7 and some server versions. Microsoft ended support for Windows 7 last year, so the decision to push an update to that software highlights the severity of the PrintNightmare flaw.

Although many Windows users don't have remote access capabilities on their home computers, business computers or people working remotely and connecting back to the office could be most affected, according to Michela Menting, a cybersecurity expert at ABI Research.

HOW BIG A DEAL IS THIS?

Windows 10 runs on about about 1.3 billion devices worldwide, according to market research firm CCS Insight, so the magnitude of the vulnerability's reach is massive. "This is a big deal because Windows 10 is the most popular desktop OS out there with over 75% market share," Menting said.

Because Windows 10 is used by desktop computers as well as some servers, it could potentially enable hackers to infiltrate a network "very quickly" and get in "practically anywhere to find the most lucrative databases and systems," Menting said.

Once Sangfor shared a proof-of-concept exploit code on the Microsoft-owned code hosting platform Github, it was copied by users before it was deleted.

HOW TO DOWNLOAD THE PATCH

Windows users can visit the Settings page, then select the Update & Security option, followed by Windows Update, or else to download the new software.

However, one researcher on Twitter how isn't entirely effective, leaving room for potential actors to still exploit the vulnerability. After this story published, a Microsoft spokesperson said the company is "not aware of any bypasses to the update" but continues to investigate the matter.

Menting said a buggy patch is in many ways like "years in cybercrime time," adding it's "highly likely" ransomware attacks or data theft could occur as a result. "There is no doubt that not every company will have updated their OS before attackers get in," she said.

THE BIG TAKEAWAY

Still, the incident serves as a reminder for both businesses and consumers to routinely update any kind of software to ensure impacted systems aren't left exposed. For anyone who believes they could be at risk to a vulnerability or isn't sure, Menting suggested disabling impacted functions until a company rolls out an official fix.

CTVNews.ca Top Stories

A team of tornado experts are investigating a path of damage through Wellington County.

Timmins-James Bay MP Charlie Angus was among approximately 120 people who gathered Sunday night for a candlelight vigil near the scene of a vicious attack against a 16-year-old in Cobalt.

A B.C. teen has a suspected case of H5N1 avian flu — the first known human to acquire the virus in Canada.

Local Spotlight

For the second year in a row, the ‘Gift-a-Family’ campaign is hoping to make the holidays happier for children and families in need throughout Barrie.

Some of the most prolific photographers behind CTV Skywatch Pics of the Day use the medium for fun, therapy, and connection.

A young family from Codroy Valley, N.L., is happy to be on land and resting with their newborn daughter, Miley, after an overwhelming, yet exciting experience at sea.

As Connor Nijsse prepared to remove some old drywall during his garage renovation, he feared the worst.

A group of women in Chester, N.S., has been busy on the weekends making quilts – not for themselves, but for those in need.

A Vancouver artist whose streetside singing led to a chance encounter with one of the world's biggest musicians is encouraging aspiring performers to try their hand at busking.

Ten-thousand hand-knit poppies were taken from the Sanctuary Arts Centre and displayed on the fence surrounding the Dartmouth Cenotaph on Monday.

A Vancouver man is saying goodbye to his nine-to-five and embarking on a road trip from the Canadian Arctic to Antarctica.