Windows 10 949 Published by

Microsoft has released KB5004948 for Windows 10 version 1607 and Windows Server 2016 to address a remote code execution exploit in the Windows Print Spooler service known as PrintNightmare.



July 7, 2021—KB5004948 (OS Build 14393.4470) Out-of-band

Highlights

This security update includes key changes as follows:

  • Updates a remote code execution exploit in the Windows Print Spooler service, known as “PrintNightmare”, as documented in  CVE-2021-34527

Improvements and fixes

This security update includes quality improvements. Key changes include:

  • Addresses a remote code execution exploit in the Windows Print Spooler service, known as “PrintNightmare”, as documented in  CVE-2021-34527. After installing this and later Windows updates, users who are not administrators can only install signed print drivers to a print server. By default, administrators can install signed and unsigned printer drivers to a print server. The installed root certificates in the system’s Trusted Root Certification Authorities trusts signed drivers. Microsoft recommends that you immediately install this update on all supported Windows client and server operating system, starting with devices that currently host the print server role. You also have the option to configure the RestrictDriverInstallationToAdministrators registry setting to prevent non-administrators from installing signed printer drivers on a print server. For more information, see  KB5005010.

If you installed earlier updates, only the new fixes contained in this package will be downloaded and installed on your device.

For more information about the resolved security vulnerabilities, please refer to the new  Security Update Guide website. 


July 7, 2021—KB5004948 (OS Build 14393.4470) Out-of-band