Security Advisories
This is where Tricerat records security advisories for ScrewDrivers. An advisory is our response to something outside the product, usually a Microsoft CVE batch that touches the Windows print stack or a vulnerability scanner flagging a component we ship. Each entry says what happened, who's affected, where things stand, and where the fix lives.
Entries here are short on purpose. The steps live on a how-to page so there's one place to keep them current. Product defects and limitations are in Known Issues, and ScrewDrivers Security covers how the product is secured in the first place.
| ID | Advisory | Affects | Status |
|---|---|---|---|
| SA-003 | September 2026 Windows print stack vulnerabilities | All v7 editions on Windows session hosts and endpoints | Informational; Microsoft's update is the fix |
| SA-002 | Visual Studio 2008 runtime flagged by vulnerability scanners | Systems that ran ScrewDrivers 7.3.0 or earlier | Remediation available |
| SA-001 | PrintNightmare (CVE-2021-34527) | All editions on Windows session hosts, Print Servers, and endpoints | Addressed; Microsoft patches compatible |
SA-003
September 2026 Windows print stack vulnerabilities
Microsoft's September 2026 security updates, released 2026-09-08, fix fifteen vulnerabilities in the Windows print stack: twelve in the Windows Print Spooler (CVE-2026-85877, CVE-2026-69346, CVE-2026-69364, CVE-2026-69921, CVE-2026-68848, CVE-2026-70564, CVE-2026-68835, CVE-2026-69309, CVE-2026-69838, CVE-2026-69552, CVE-2026-69569, CVE-2026-69344), two in the Windows HTTP Print Provider (CVE-2026-69769, CVE-2026-69623), and one in the Print Workflow service (CVE-2026-69602). ScrewDrivers is built on the Print Spooler, so the spooler fixes apply to every ScrewDrivers deployment. ScrewDrivers doesn't use the HTTP Print Provider or the Print Workflow service.
Affects: All ScrewDrivers v7 editions on Windows session hosts, Print Servers, and Windows endpoints. These are Windows vulnerabilities, not ScrewDrivers defects.
Status: Informational. Microsoft's September 2026 update is the fix. The linked article also describes optional hardening steps that some organizations evaluate; they aren't Tricerat requirements, and they should be tested in your environment before wide deployment. See September 2026 Windows Print Stack Vulnerabilities.
SA-002
Visual Studio 2008 runtime flagged by vulnerability scanners
ScrewDrivers 7.3.0 and earlier installed the Visual Studio 2008 runtimes (VC9) for the legacy v6 console. Version 7.3.1 dropped that requirement, but the runtime stays behind on systems that ran an older version, and vulnerability scanners flag it for MS09-035.
Affects: Systems that ran ScrewDrivers 7.3.0 or earlier and haven't had the runtime removed.
Status: Remediation available. Update ScrewDrivers, then remove the runtime or apply Microsoft's MFC Security Update. See Addressing the Visual Studio 2008 Runtime Vulnerability in ScrewDrivers.
SA-001
PrintNightmare (CVE-2021-34527)
Published July 2021. A remote code execution vulnerability in the Windows Print Spooler pushed Microsoft to release out-of-band patches on 2021-07-06, and pushed some organizations toward workarounds that lock down the spool folder or disable the spooler outright. ScrewDrivers works with Microsoft's patches. The spool-folder workaround breaks ScrewDrivers unless SYSTEM keeps access to the ScrewDrivers driver files, and disabling the spooler stops all printing.
Affects: All editions on Windows session hosts, Print Servers, and endpoints.
Status: Addressed. Apply Microsoft's patches. Configuration notes for the workarounds are in PrintNightmare (CVE-2021-34527) Compatibility.
Reporting a vulnerability
If you think you've found a security vulnerability in ScrewDrivers, contact Tricerat Support or email Support@tricerat.com. Please give us a chance to respond before posting details publicly.