Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

PrintNightmare, Critical Windows Print Spooler Vulnerability (Windows Admins: Disable Print Spooler NOW)
US Cybersecurity & Infrastructure Security Agency ^ | June 30, 2021 | US-CERT-CISA Agency

Posted on 07/01/2021 7:55:16 AM PDT by dayglored

[Dayglored Note: This is primarily for Windows Administrators, but is of potential concern to ALL Windows users.]

Also see:
Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller
PrintNightmare: Windows Zero-Day Accidentally Disclosed by Chinese Researchers
Public Windows PrintNightmare 0-day exploit allows domain takeover

PrintNightmare, Critical Windows Print Spooler Vulnerability

Original release date: June 30, 2021

The CERT Coordination Center (CERT/CC) has released a VulNote for a critical remote code execution vulnerability in the Windows Print spooler service, noting: “while Microsoft has released an update for CVE-2021-1675, it is important to realize that this update does not address the public exploits that also identify as CVE-2021-1675.” An attacker can exploit this vulnerability—nicknamed PrintNightmare—to take control of an affected system.

CISA encourages administrators to disable the Windows Print spooler service in Domain Controllers and systems that do not print. Additionally, administrators should employ the following best practice from Microsoft’s how-to guides, published January 11, 2021: “Due to the possibility for exposure, domain controllers and Active Directory admin systems need to have the Print spooler service disabled. The recommended way to do this is using a Group Policy Object.”


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: activedirectory; ad; dc; domaincontroller; printnightmare; printspooler; vulnerability; windows; windowspinglist
Navigation: use the links below to view more comments.
first 1-2021-37 next last
DISABLE PRINT SPOOLING NOW. JUST DO IT.
1 posted on 07/01/2021 7:55:16 AM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; bajabaja; ...
Windows Print Spooler -- STOP IT ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 07/01/2021 7:56:16 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

For the life of me, I don’t understand why anyone who has a choice would run Windows. It’s been a nightmare since inception.


3 posted on 07/01/2021 7:56:50 AM PDT by dinodino ( )
[ Post Reply | Private Reply | To 1 | View Replies]

To: dinodino

This is a hot mess. Millions of businesses have to stop printing until Microsoft fixes this, or risk getting pwned by an active exploit in the wild? WOW.


4 posted on 07/01/2021 7:59:32 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

I checked on my Win10 box where I am Admin and PrintSpooler is running.

This advisory aimed at Admins will be ignored by 99.9% of users. Especially those who like to print.


5 posted on 07/01/2021 8:03:14 AM PDT by bigbob
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Nah, you really shouldn’t need to run print spooler on your domain controller anyway.


6 posted on 07/01/2021 8:03:30 AM PDT by z3n
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

Omgosh, this explains what happened to our printers recently!


7 posted on 07/01/2021 8:07:42 AM PDT by browniexyz
[ Post Reply | Private Reply | To 1 | View Replies]

To: dinodino

Sometimes you have to live with the environment you inherit because you aren’t just dealing with your preferences, you’re dealing with everyone else’s learning curve, or interoperability with other organizations you do business with.


8 posted on 07/01/2021 8:08:43 AM PDT by NicoDon
[ Post Reply | Private Reply | To 3 | View Replies]

To: bigbob
> This advisory aimed at Admins will be ignored by 99.9% of users. Especially those who like to print.

Sadly, true. Win10 users at home don't necessarily realize that they are admins, or that the spooler is running by default, etc.

> ...those who like to print ignore security issues

99.9%, as you said.

9 posted on 07/01/2021 8:11:52 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 5 | View Replies]

To: browniexyz
> Omgosh, this explains what happened to our printers recently!

Maybe, or maybe not. Printers, and Windows printing, have plenty of their own problems even before this came out. I don't know how widespread the exploits are yet.

10 posted on 07/01/2021 8:14:06 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

Does the print spooler run on stand-alone Windows installations?


11 posted on 07/01/2021 8:17:55 AM PDT by MortMan (Shouldn't "palindrome" read the same forward and backward?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Spooler?...Spooler?...Spooler?...


12 posted on 07/01/2021 8:18:39 AM PDT by deoetdoctrinae (Gun-free zones are playgrounds for criminals.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dinodino

Because pretty much all business specific programs are and have been created for windows. For personal use however, Linux/Ubuntu is the way to go. No stupid long restarts on update. No a big target for hackers like windows is. The system doesn’t get bogged down over time due to updates or installing programs. Generally safer and better performing. And it’s free for the OS and programs. My favorite right now is Kubuntu with the Plasma desktop. Fast and fancy. Looks like I need to do an update right now. 10:18 Central time. brb


13 posted on 07/01/2021 8:18:43 AM PDT by Pollard
[ Post Reply | Private Reply | To 3 | View Replies]

To: MortMan
> Does the print spooler run on stand-alone Windows installations?

Yes. It's on all Windows computers, and is enabled to run by default.

Turning it off (disabling it) requires administrator-level permissions, but most standalone Windows systems have a single user (the one who set it up, or first logged in) who is an administrator.

14 posted on 07/01/2021 8:24:49 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 11 | View Replies]

To: Pollard

10:18 to 10:26 - 182mb update done, no restart even though linux-firmware was 98mb of the update.


15 posted on 07/01/2021 8:28:09 AM PDT by Pollard
[ Post Reply | Private Reply | To 13 | View Replies]

To: dayglored

Reason 2,873 why I’m staying with, and enjoying Win-7 Pro x64.


16 posted on 07/01/2021 8:32:18 AM PDT by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MortMan

#11 Yes and if you disable the Print spooler then you cannot print.


17 posted on 07/01/2021 8:39:56 AM PDT by minnesota_bound (I need more money. )
[ Post Reply | Private Reply | To 11 | View Replies]

To: dayglored

18 posted on 07/01/2021 8:40:15 AM PDT by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

My tech savvy son helps me with my computer (I’m sadly lacking in skills). He told me to hit control pee to print. I said if I could do that, I wouldn’t be wearing adult diapers.


19 posted on 07/01/2021 8:50:06 AM PDT by BipolarBob (Remember the good ol days when we worried about being bombed by the Russian President but not ours?)
[ Post Reply | Private Reply | To 18 | View Replies]

To: carriage_hill

“Reason 2,873 why I’m staying with, and enjoying Win-7 Pro x64.”

Same here — we’re hooked on 7 Pro until and will stick with it to the bitter end, whenever that may come.


20 posted on 07/01/2021 9:02:31 AM PDT by AnglePark
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-37 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson