The PrintNightmare continues: Microsoft confirms presence of vulnerable code in all versions of Windows
- Reference: 1625230865
- News link: https://www.theregister.co.uk/2021/07/02/printnightmare_cve/
- Source link:
The megacorp said it was still investigating whether the vulnerability was exploitable in every version, but domain controllers are indeed affected.
Microsoft also confirmed that this nasty was distinct from [2]CVE-2021-1675 , which was all about a different attack vector and a different vulnerability in RpcAddPrinterDriverEx() . The June 2021 Security update dealt with that, according to Microsoft, and did not introduce the new badness. That had existed prior to the update.
[3]
The Windows giant also confirmed that the PrintNightmare vulnerability was being exploited in the wild.
[4]
[5]
"PrintNightmare" is well named, since it permits an attacker to run arbitrary code with SYSTEM privileges. As The Reg reported, a miscreant successfully exploiting the vulnerability (via a flaw in the Windows Printer Spooler service) can install programs, fiddle with data, or create new accounts with full user rights.
"An attack," said Microsoft, "must involve an authenticated user calling RpcAddPrinterDriverEx()."
[6]PrintNightmare: Kicking users from Pre-Windows 2000 legacy group may thwart domain controller exploitation
[7]Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller
[8]IBM email fiasco complicates sales deals, is worse than biz is letting on – sources
[9]We've found another reason not to use Microsoft's Paint 3D – researchers
The zero-day was [10]accidentally disclosed earlier this week when an infosec research group published proof-of-concept code for the exploit, mistakenly thinking it had already been patched as part of CVE-2021-1675. It hadn't, and panic ensued despite the code being hurriedly pulled.
[11]Mitigations suggested so far have included shutting down the Windows Print Spooler service on domain controllers not used for printing or yanking users from a pre-Windows 2000 legacy group.
[12]
Microsoft's own workarounds start with disabling the Print Spooler service and end with disabling inbound remote printing through group policy. The former stops all printing, while the latter will at least allow local printing even if print server duties are left broken.
It remains very much an evolving situation as Microsoft scrambles to deal with the problem. The company has yet to assign a CVSS score or severity to the vulnerability, only saying: "We are still investigating."
Be that as it may, a vuln that can gift an attacker SYSTEM rights on a domain controller is a very, very bad thing indeed. ®
Get our [13]Tech Resources
[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1675
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YN84HoXPXKeJnA-WQ2woZQAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YN84HoXPXKeJnA-WQ2woZQAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YN84HoXPXKeJnA-WQ2woZQAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/07/01/printnightmare_windows_fix/
[7] https://www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/
[8] https://www.theregister.com/2021/07/01/ibm_email_disruption_sales/
[9] https://www.theregister.com/2021/06/16/3d_paint_vuln/
[10] https://www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/
[11] https://www.theregister.com/2021/07/01/printnightmare_windows_fix/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YN84HoXPXKeJnA-WQ2woZQAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Re: As much as I like to dump on microsoft a pile...
Company size doesn't and shouldn't matter. Think of all those small companies, charities/not-for-profit that probably only have one server, and who probably also have a userbase that could fall victim to malware. Remember that any authenticated user can now own the domain....or put differently, Mary in Accounts just needs to run some code from an email or URL and she just potentially created a new domain admin account.
Re: As much as I like to dump on microsoft a pile...
I've supported several companies in my time who had only 1 server (a DC) and that's it, with everything running on it: DHCP, DNS, ADDS, ADCS, Print Services, Antivirus management, etc, etc. I said they should have at least 2 DCs, a seperate file server and a print server (and more if possible). Answer? Costs too much for the servers and the licensing. You can lead a horse to water, but ...
Re: As much as I like to dump on microsoft a pile...
Go and have a look at r/sysadmin on Reddit. You'll find it is very common judging by the wailing ...
Re: As much as I like to dump on microsoft a pile...
I got an email this morning saying print services were no longer available at my university research institute until further notice because of this. What research goes on there? Mainly cybersecurity stuff...
Maybe they're overreacting, I don't know, but I didn't have the greatest faith in them beforehand.
Could Be A Disaster
While I rarely print anything personally or professionally, there are some people who need to print documents with a great deal of regularity. Telling them to stop printing because the Rejects of Redmond haven't fixed a bug (I doubt they would have arsed themselves to fix it if wasn't for the 'accidental' release) is beyond idiotic.
Re: Could Be A Disaster
People who need to print often are unlikely to be hanging off a domain controller for it.
Most printing is now directly spooled into a target printe from the machine that generates the print.
Sustainability
This is a big buzzword in our place at the moment - tempting to completely diable printing and say it's to meet our sustainability goals :-)
All versions of Windows?
So it's existed since Win1.0 & they've never bothered to fix it? Or perhaps you meant all current versions which would limit it to only Win10 and the upcomming Win11? Please let us know so that we may further lock down our WinXP boxen to mitigate such inherent imbicility thanks.
Re: All versions of Windows?
Apparently insufficient numbers of people have been hanging printers off domain controllers for this to be discovered earlier, which, to me, is not a bad thing.
Re: All versions of Windows?
Actually, if you put it that way, it's somehow a bit less terrifying. Thank you for that. Have a virtual beer on me!
Could have been a different title....
"Decades after launch, Microsoft realizes their printer software is buggy. Users question what took them so long."
As much as I like to dump on microsoft a pile...
.. and this bug is a nasty one if you've got a very specific setup... I can't imagine that many people have taken the decision to a) hang a load of peripherals off their domain controller and b) be large enough that they are panicking about internal users exploiting the vulnerability.
Surely anyone of any size is using a print server rather than dumping that load on the domain controller?