News: 1625635239

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft patches PrintNightmare — even on Windows 7 — but the terror isn’t over

(2021/07/07)


Microsoft has issued out-of-band patches for the [1]PrintNightmare print spooler bug that allows lets remote Windows users execute code as system on your domain controller.

The bug, designated [2]CVE-2021-34527 , is present in all versions of Windows.

However, Microsoft’s [3]advisory states: “Updates are not yet available for Windows 10 version 1607, Windows Server 2016, or Windows Server 2012.”

[4]

Those are worrying omissions, as the first two versions mentioned are five years old and could well be quite widely used. Windows Server 2012 is currently in Extended Support — a paid service. Customers therefore have a security issue to worry about and perhaps also bone to pick with Microsoft, given that Windows 7 is also in Extended Support .

[5]The PrintNightmare continues: Microsoft confirms presence of vulnerable code in all versions of Windows

[6]PrintNightmare: Kicking users from Pre-Windows 2000 legacy group may thwart domain controller exploitation

[7]Microsoft fixes the thing it broke via another dose of out-of-band patching to deal with BSOD printing problems

Microsoft recommends prompt application of its patches, but its advisory also offers a workaround if you’re not able to install the software.

The emergency patches are Microsoft’s second in a week. On June 30th the company [8]issued another to crimp an Adobe bug. They also mark Microsoft’s second print-related rush job in 2021 alone, after a March fix [9]left some Windows 10 users unable to print , requiring a patch-up job to fix the first patch. ®

Get our [10]Tech Resources



[1] https://www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/

[2] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34527

[3] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YOV7QTdesInyNnp3rlKONgAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.theregister.com/2021/07/02/printnightmare_cve/

[6] https://www.theregister.com/2021/07/01/printnightmare_windows_fix/

[7] https://www.theregister.com/2021/03/16/microsoft_printer_fix/

[8] https://www.theregister.com/2021/06/30/microsoft_internet_explorer_pdf_patch/

[9] https://www.theregister.com/2021/03/18/windows_printer_still_broken/

[10] https://whitepapers.theregister.com/



It is about time

Anonymous Coward

that the 'C' level execs in Microsoft took note of just how much of a dogs breakfast Windows code really is and has been since the day BillyG went dumpster diving.

Then they'll laugh as they cash in their share options to buy that new boat/plane/island.

This is just another case of Windows not being fit for purpose and is why many here keep referring to the whole windows experience as a 'perpetual beta' (or in extreme cases, a perpetual alpha) code release.

Why so many businesses have chained themselves to this pile of bovine excrement is one of the things that will puzzle the historians of the 22nd century... If we as a species last that long that is...

Re: It is about time

Trigun

WIndows is certainly not perfect, but I think your analysis is a tad histrionic.

Re: It is about time

AMBxx

He's one of those Linux user experts who shouts about not using Windows since 1985!

Re: It is about time

Anonymous Coward

Win10 isn't perfect is true, but then it's so far from even 'barely adequate' that it beggers belief. How many times does a supposedly stable OS have to be rendered FUBAR by a fix released to patch an issue caused by the previous fix before you acknowledge that all is not right in MSHQ? How many times does a site like this one have to publish a funny-like-a-car-crash story about how MS has rearranged the deck chairs (UI/UX reshuffling) before you notice that the Titanic is sinking? How much of your supposedly private/confidential data do they need to suck up under the guise of "telemetry" before you wake up to the fact that if your computer runs Win10 it's not >YOUR< computer any longer?

FFS all you need do is surf the archives of this site to find a mountain of angst, annoyance, frustration, dispair, & forehead-on-the-desktop-pounding examples of Yet Another Microsoft FuckUp that it boggles the mind how anyone >CAN< consider Win10 fit for purpose & not defective by design.

"I turned my computer off last night and went to bed. It was working fine. Then I woke up and turned it back on to watch it updating itself with the latest MS 'improvement'. Now the calculator no longer works. How the fuck do you break something as simple as calculator?" is the type of head-shaking-in-dismay style of "improvements" that Win10 rams down your throat so how >precisely< can you justify it as fit for purpose when all signs indicate the exact opposite?

I'm not trying for histerionics - I'm asking an honest question as to how you (or anyone) can claim Win10 has >NOT< been a dumpster pyre from day one...

Re: It is about time

AndrueC

Why so many businesses have chained themselves to this pile of bovine excrement is one of the things that will puzzle the historians of the 22nd century... If we as a species last that long that is...

It won't puzzle anyone who understands the IT industry. Those people will understand that throughout its lifetime it provided the features and services that people needed to get their job done. That despite its numerous flaws it was still good enough to help build the complex and successful IT ecosystems of the 20th and 21st century.

The only people that genuinely think that Windows is a bad operating system are those with blinkered eyes such as yourself. For everyone else the plain fact of the matter is that Windows is still with us. It's still being used by millions of people at home and at work around the world . It didn't get there by being 'bovine excrement'.

Re: It is about time

Anonymous Coward

Another thought... If you as an admin are serious about security, why have you got services running when not required?

Unless your box is a print server, disable remote printing and the print spooler... No service running = no attack surface.

Why?

Mike 137

Can anyone explain why the print spooler service is left running on a domain controller? Does anyone harden any system these days? We used to - it was my specific job on one major project in the days of NT4.

Re: Why?

Mishak

Probably not likely in a lot of places, but there will be some small businesses (perhaps two in the office, a couple on the road) that have one box that does everything (and can accept a few days of down time if there are problems).

Re: Why?

General Purpose

Maybe in rather a lot of places. 96% of UK businesses have less than 10 employees and that's not counting the charities.

Re: Why?

Pascal Monett

That's funny. I asked that same question a while ago and [1]I got downvoted .

[1] https://forums.theregister.com/forum/all/2021/06/30/windows_print_spool_vuln_rce/

The reader this message encounters not failing to understand is cursed.