Understanding printer vulnerabilites (CVE-2016-3238)

preview_player
Показать описание
The vulnerability stems from a Windows process that allows users to quickly search for, add, and use printers at home, in the office and over the Internet. Armed with system-level controls, the malware can then spread laterally from one machine across an entire network.

Read more about the CVE-2016-3238 printer vulnerability:

Рекомендации по теме
Комментарии
Автор

Your video did not show what happened when the dialog box displayed. Are you assuming the user clicks the OK button to infect or would clicking on the red X to close the dialog do the same thing?
How can this vulnerability be tested? I assume such vulnerabilities are handled by most firewall software out there would that be safe to say?

rssx
Автор

what preferences did u use use to generate the listener ?

androidbest
Автор

So is it dangerous to pick up someone's used printer? Can the actual printer have malware?

Luis-qulk
Автор

windows update is stuck on checking for updates for 3 hours and counting, i guess linux is literally my only choice now since i will not be able to patch this thing, what a great time for windows update to break, i guess its a coincidence i was working fine since 2009 and 2 weeks from the end of windows 10 offer this printer thing pops up and suddenly windows update stops working

just a coincidence

nookchorris
Автор

I have a sample from the wild of something like this if anyone would like to see.

internetwarrior