Let’s bust the PrintNightmare bug once and for all

The PrintNightmare vulnerability has been affecting Windows users for months. Despite multiple attempts at patches, problems are still persisting. Understandably, the debacle has concerned the cyber community.

What is PrintNightmare?

PrintNightmare is a vulnerability that affects the Microsoft Windows Print Spooler Service. The ‘Print Spooler’ is enabled by default in all Windows clients and servers. The service manages print jobs by loading printer drivers, receiving print files, queuing/ scheduling them, and more.

The printing issue came about in June as a result of the Windows ‘KB5004945’ updates which affects virtually all versions of Windows systems. Microsoft is now urging people to uninstall the update as soon as possible.

The vulnerability has become a primary target for ransomware groups, as it allows them to gain total control over an affected system. All they need to do is is find a compromised workstation to gain access to the whole network. By abusing system privileges, they can install programs; view, alter, or delete data; or create new accounts with full user rights.

In July, Microsoft released an emergency patch to address the vulnerability but it was subsequently bypassed. The patch only addressed the RCE component, which meant that an attacker could still escalate regular user privileges to gain system-level privileges.

How PenTera can help

PenTera is a fully automated platform that requires no prior knowledge of the IT environment in question. The solution can see what nobody else can, providing instant discovery and exposure validation across the entire IT infrastructure.

With the latest version of PenTera v4.5.5, the PrintNightmare vulnerability can now be identified. What’s more, it exposes, exploits, prioritises and remediates PrintNightmare, as well as pinpointing all the possible attack paths a hacker may take to compromise your organisation.

PenTera is the only Penetration Testing tool that can do all of this automatically, without any agent, with a completely safe-by-design approach. Thanks to constant updates, it protects against the most up to date threats and attacker techniques.

Ready to adopt a more proactive approach to your cybersecurity?

To learn more about Pentera, check out our latest podcast episode here.

Apr 16 2026

Supply Chain Risk Has Changed: How to Maintain Visibility Across Your Third Parties

Third-party risk management has shifted from a procurement checkbox into a core operational and governance concern, largely because most organisations now depend on a...
Apr 10 2026

The Cyber Security & Resilience Bill: What It Is, Where It’s Heading, and Why You Shouldn’t Wait

Last updated: 10th April 2026 If you manage third-party risk, supplier assurance, or cyber compliance, the UK’s Cyber Security and Resilience Bill will directly change...
Mar 14 2026

Ransomware Report 2025: The Threat Is Far From Over

At first glance, the second half of 2025 looked like progress for defenders. Reported ransomware victims fell slightly. But the wider picture tells a different story:...
Jan 20 2026

Join Us in Supporting the Great Gloucestershire Mouse Hunt

Core to Cloud is proud to support the Great Gloucestershire Mouse Hunt, a county-wide campaign collecting essential computer peripherals to help improve access to...
Jan 14 2026

From Defence to Resilience: A Strategic Framework for Ransomware Preparedness

Ransomware has evolved into a highly organised and commercially driven threat, capable of bypassing traditional cyber security controls. As attacks become more...
Nov 11 2025

Core to Cloud Partners with The ITSA Digital Trust to Empower Digital Inclusion and Support Sustainable Technology

At Core to Cloud, we’ve always believed that technology should make a positive difference by protecting people, enabling innovation, and building a more inclusive...
Oct 27 2025

Human-led, AI-Enhanced MDR: Rethinking the Balance of People and Technology

By Phil Howe, CTO at Core to Cloud It’s getting colder and wetter outside, and to some the security landscape may feel more complex than ever. Threat actors are faster,...
Oct 22 2025

From Warning to Action: The NCSC Calls on UK Organisations to Build Resilience

In its 2025 Annual Review, the UK’s National Cyber Security Centre (NCSC) issued one of its clearest warnings to date: organisations must prepare for a day when their...
Jun 25 2025

Think You’re Ready for a Cyberattack? Prove It.

In the face of increasing cyber threats, most organisations have invested heavily in technology - firewalls, antivirus, endpoint protection, and cloud security. But...
Jun 13 2025

Secure & Strong Partners with Women in Tech & Cyber Hub (WITCH)

At Core to Cloud, we believe the future of cybersecurity is inclusive, empowering, and community-driven. That’s why we’re proud to announce a meaningful new partnership...

Trusted by CISOs and IT teams at over 150 organisations