Microsoft announced a new Windows Protected Print Mode, introducing significant security enhancements to the Windows print system.
Notably, once WPP rolls out and gets enabled by default on all Windows systems, Redmond will shift away from running the built-in Print Spooler service as SYSTEM but, instead, launching it as a restricted service.
This will drastically reduce its access to resources and privileges, mitigating the appeal of the Spooler process as a potential target for exploitation.
Microsoft will remove several attack vectors previously exploited by malicious actors targeting Windows users.
Numerous RPC endpoints and various legacy components targeted in the past will be removed, according to Norman.
Microsoft also ensured that these security improvements would not affect customers with older printers, as they could enable legacy support.
This comes on the heels of Redmond announcing that Windows Update will eventually stop third-party printer driver delivery over the next four years as part of a gradual and significant shift in its printer driver strategy.
Starting in 2025, Microsoft will block driver submissions from printer vendors, so no new third-party printer drivers will be made available through Windows Update.
By 2026, Redmond plans to adjust the printer driver ranking system, prioritizing in-house Windows Internet Printing Protocol Class drivers.
It will stop distributing third-party printer driver updates via Windows Update in 2027 unless it provides security fixes.
Users will still be able to install printer drivers provided by vendors through their websites as standalone installation packages.
Microsoft also plans to continue patching older printer drivers as long as the associated Windows versions are within their Support Lifecycles.
Microsoft confirms Windows bug renames printers to HP LaserJet M101-M106. Avira antivirus causes Windows computers to freeze after boot.
Microsoft to let Windows 10 home users buy Extended Security Updates.
Windows 11 KB5032288 update improves Copilot, fixes 11 bugs.
Windows 10 KB5032278 update adds Copilot AI assistant, fixes 13 bugs.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Sat, 16 Dec 2023 16:50:19 +0000