I was going to listen to Security Now on a lunch break later today, but reading the podcast notes, I see that Microsoft does not consider some of the issues to be real issue. And Point
And Print is involved here somehow.
So the current best recommendation is:
In other words, apply the out-of-band patch and be sure that the two keys noted above under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsNT\Printers\PointAndPrint
do not exist. If you don’t know you need them, remove them for safety and security.
The optioons to remove are:
NoWarningNoElevationOnInstall = 0 (DWORD) or not defined (default setting)
UpdatePromptSettings = 0 (DWORD) or not defined (default setting)
Having NoWarningNoElevationOnInstall set to 1 makes your system vulnerable by design.
So if you or some other application did not change anything in the registry, then you are safe with the latest patches. If you have those keys and they are set to 1, then you are vulnerable and this is not going to be fixed.
It is likely that you don't have those keys, but double check to be sure. Especially given that the fixed issue is a local privilege escalation, and the other one is a remote code execution.