Microsoft Windows Print Spooler Uzaktan Kod Çalıştırma Güvenlik Zafiyeti

Microsoft Windows Print Spooler Uzaktan Kod Çalıştırma Güvenlik Zafiyeti

Microsoft tarafından Windows Print Spooler servisi ile ilgili olarak uzaktan kod yürütmeye neden olacak CVSS V3.1 Skoru 9.8 olan yeni bir kritik* güvenlik zafiyeti yayınlanmıştır.

Microsoft Windows Print Spooler Uzaktan Kod Çalıştırma Güvenlik Zafiyeti

Print Spooler ile ilgili güvenlik zafiyetleri CVE-2021-1675 ile başlamıştır. Bazen PrintNightmare olarak da adlandırılan bu durum ile ilgili yayınlanan diğer güvenlik zafiyetleri aşağıdadır;

  • CVE-2021-34527
  • CVE-2021-34481
  • CVE-2021-36936
  • CVE-2021-36947
  • CVE-2021-34483
  • CVE-2021-36958

Etkilenen Sistemler

Windows İşletim Sistemleri/Windows Print Spooler

IoC’ler

-

Çözüm Önerileri

Aşağıdaki belirtilen hususları takip etmeniz/yapmanız önerilmektedir.

  • Barikat’ın olay ile ilgili bildirimlerini takip edin.
  • Microsoft’un yayınlayacağı güncellemeleri takip edin.
  • Yeni yamalar yayınlanana kadar Print Spooler servisini kapatmak kısa süreli bir çözüm olarak gündeme getirilebilir.
  • CVE-2021-36936 güvenlik zafiyeti ile ilgili olarak yayınlanan aşağıdaki yamaların indirilmesi önerilmektedir. Ayrıca Açıklama bölümünde belirtilen diğer Güvenlik Zafiyetlerinin yamaları da indirilebilir.
Ürün Makale Güvenlik Yaması
Windows Server 2012 R2 (Server Core installation) 5005076 Monthly Rollup
Windows Server 2012 R2 (Server Core installation) 5005106 Security Only
Windows Server 2012 R2 5005076 Monthly Rollup
Windows Server 2012 R2 5005106 Security Only
Windows Server 2012 (Server Core installation) 5005099 Monthly Rollup
Windows Server 2012 (Server Core installation) 5005094 Security Only
Windows Server 2012 5005099 Monthly Rollup
Windows Server 2012 5005094 Security Only
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5005088 Monthly Rollup
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5005089 Security Only
Windows Server 2008 R2 for x64-based Systems Service Pack 1 5005088 Monthly Rollup
Windows Server 2008 R2 for x64-based Systems Service Pack 1 5005089 Security Only
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5005090 Monthly Rollup
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5005095 Security Only
Windows Server 2008 for x64-based Systems Service Pack 2 5005090 Monthly Rollup
Windows Server 2008 for x64-based Systems Service Pack 2 5005095 Security Only
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5005090 Monthly Rollup
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5005095 Security Only
Windows Server 2008 for 32-bit Systems Service Pack 2 5005090 Monthly Rollup
Windows Server 2008 for 32-bit Systems Service Pack 2 5005095 Security Only
Windows RT 8.1 5005076

Monthly Rollup

Windows 8.1 for x64-based systems 5005076 Monthly Rollup
Windows 8.1 for x64-based systems 5005106 Security Only
Windows 8.1 for 32-bit systems 5005076 Monthly Rollup
Windows 8.1 for 32-bit systems 5005106 Security Only
Windows 7 for x64-based Systems Service Pack 1 5005088 Monthly Rollup
Windows 7 for x64-based Systems Service Pack 1 5005089 Security Only
Windows 7 for 32-bit Systems Service Pack 1 5005088 Monthly Rollup
Windows 7 for 32-bit Systems Service Pack 1 5005089 Security Only
Windows Server 2016 (Server Core installation) 5005043 Security Update
Windows Server 2016 5005043 Security Update
Windows 10 Version 1607 for x64-based Systems 5005043 Security Update
Windows 10 Version 1607 for 32-bit Systems 5005043 Security Update
Windows 10 for x64-based Systems 5005040 Security Update
Windows 10 for 32-bit Systems 5005040 Security Update
Windows Server, version 20H2 (Server Core Installation) 5005033 Security Update
Windows 10 Version 20H2 for ARM64-based Systems 5005033 Security Update
Windows 10 Version 20H2 for 32-bit Systems 5005033 Security Update
Windows 10 Version 20H2 for x64-based Systems 5005033 Security Update
Windows Server, version 2004 (Server Core installation) 5005033 Security Update
Windows 10 Version 2004 for x64-based Systems 5005033 Security Update
Windows 10 Version 2004 for ARM64-based Systems 5005033 Security Update
Windows 10 Version 2004 for 32-bit Systems 5005033 Security Update
Windows 10 Version 21H1 for 32-bit Systems 5005033 Security Update
Windows 10 Version 21H1 for ARM64-based Systems 5005033 Security Update
Windows 10 Version 21H1 for x64-based Systems 5005033 Security Update
Windows 10 Version 1909 for ARM64-based Systems 5005031 Security Update
Windows 10 Version 1909 for x64-based Systems 5005031 Security Update
Windows 10 Version 1909 for 32-bit Systems 5005031 Security Update
Windows Server 2019 (Server Core installation) 5005030 Security Update
Windows Server 2019 5005030 Security Update
Windows 10 Version 1809 for ARM64-based Systems 5005030 Security Update
Windows 10 Version 1809 for x64-based Systems 5005030 Security Update
Windows 10 Version 1809 for 32-bit Systems 5005030 Security Update

CVE / CWE

CVE-2021-36936

Ek Bilgiler

* CVSS 3.1 skoru (10 üzerinden) 7.0-8.9 olanlar “yüksek”, 9.0-10.0 olanlar “kritik” zafiyet olarak değerlendirilmektedir.