Remote Code Execution Vulnerability in Microsoft Print Spooler (PrintNightmare)

Components Affected

  • Windows 10 for 32-bit systems & x64-based systems
  • Windows 10 Version 1607 for 32-bit systems & x64-based systems
  • Windows 10 Versions 1809, 1909, 2004, 20H2, 21H1 for 32-bit systems, x64-based systems, and ARM64-based systems
  • Windows 7 and 8.1 for 32-bit systems SP1 & x64-based systems SP1
  • Windows RT 8.1
  • Windows Server 2008 for 32-bit systems SP2 & x64-based systems SP2
  • Windows Server 2008 R2 for x64-based systems SP1
  • Windows Server 2012, 2012 R2, 2016 & 2019
  • Windows Server 2008 for 32-bit systems SP2 (Server Core installation) & x64-based systems SP2 (Server Core installation)
  • Windows Server 2008 R2 for x64 based systems SP1 (Server Core installation)
  • Windows Server 2012, 2012 R2, 2016, 2019, version 2004 & version 20H2 (Server Core installation)

Threat Level

High

Overview

Microsoft officially confirmed a remote code execution vulnerability called “PrintNightmare” affecting windows print spooler is actively exploited by the attackers.

Description

The vulnerability “PrintNightmare” exists in the Microsoft Print Spooler service due to a failure to restrict access to the RpcAddPrinterDriverEx() function. A remote authenticated user could exploit this vulnerability by sending a specially crafted request to an affected system.

Impact

  • Executing unwanted applications
  • Malware distribution

Solution/ Workarounds

Note – Workarounds listed below may impact existing business functions and should be implemented after proper assessment.

Disable the Print Spooler Service on Domain Controllers and systems that are not used for printing.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

https://docs.microsoft.com/en-us/defender-for-identity/cas-isp-print-spooler

Disable inbound remote printing through group policy .

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

https://docs.microsoft.com/en-us/troubleshoot/windows-server/printing/use-group-policy-to-control-ad-printer

Users are also advised to restrict access to ports 445/TCP and 135/TCP at network perimeter.

Reference

Disclaimer

The information provided herein is on an “as is” basis, without warranty of any kind.

Citation: SLCERT Cyber Security Alerts