Microsoft fixes critical PrintNightmare and Office document vulnerabilities in Windows 10

Surface Laptop 4 Amd 2021 Lid
Surface Laptop 4 Amd 2021 Lid (Image credit: Daniel Rubino / Windows Central)

What you need to know

  • Microsoft addressed 66 security vulnerabilities in its September 2021 Patch Tuesday update.
  • The update addresses the PrintNightmare and Office document vulnerabilities.
  • The PrintNightmare and Office document vulnerabilities were rated as critical.

We broke down how attackers can use this vulnerability in greater detail last week. To summarize, the vulnerability labeled as Windows CVE-2021-40444 can be exploited by using ActiveX controls in an Office document. If people are tricked into opening files and disabling Protected View, an attacker can get malware onto a computer.

Microsoft's documentation on the security vulnerability now includes an update:

Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.

The Office document vulnerability could be used in conjunction with other issues, such as the recent bug in Outlook that showed spoofed domains inside genuine contact cards.

Microsoft also released an update for the Windows Print Spooler Remote Code Execution Vulnerability, which is labeled CVE-2021-36958. The Print Spooler vulnerability caused a wide range of problems, including attackers being able to place ransomware onto vulnerable PCs.

Security expert Benjamin Delpy confirmed to BleepingComputer that the bug was fixed.

Microsoft has a full list of all addressed security issues from the September 2021 Patch Tuesday update.

Sean Endicott
News Writer and apps editor

Sean Endicott is a news writer and apps editor for Windows Central with 11+ years of experience. A Nottingham Trent journalism graduate, Sean has covered the industry’s arc from the Lumia era to the launch of Windows 11 and generative AI. Having started at Thrifter, he uses his expertise in price tracking to help readers find genuine hardware value.

Beyond tech news, Sean is a UK sports media pioneer. In 2017, he became one of the first to stream via smartphone and is an expert in AP Capture systems. A tech-forward coach, he was named 2024 BAFA Youth Coach of the Year. He is focused on using technology—from AI to Clipchamp—to gain a practical edge.