News: 1625681888

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft struggles to wake from its PrintNightmare: Latest print spooler patch can be bypassed, researchers say

(2021/07/07)


Any celebrations that Microsoft's out-of-band patch had put a stop PrintNightmare shenanigans may have been premature.

The emergency [1]update [2]turned up yesterday for a variety of Microsoft operating systems; little-used products like Windows Server 2012 and 2016 were excluded from the interim release.

While it initially appeared the remote-code execution (RCE) aspect of the security bug had been resolved, the local privilege escalation (LPE) hole remained, judging by [3]the findings of a [4]number of security researchers.

[5]

Then it got worse as demonstrations emerged apparently showing RCE and LPE were still possible on a fully patched server. That means it's still possible for an authenticated user to get admin-level privileges on a local or remote machine running the Windows print spooler service. Proof-of-exploit code is floating around the internet; miscreants just need to make use of [6]UNC to bypass the patch.

Dealing with strings & filenames is hard😉

New function in [7]#mimikatz 🥝to normalize filenames (bypassing checks by using UNC instead of \\server\share format)

So a RCE (and LPE) with [8]#printnightmare on a fully patched server, with Point & Print enabled

> [9]https://t.co/Wzb5GAfWfd [10]pic.twitter.com/HTDf004N7r — 🥝 Benjamin Delpy (@gentilkiwi) [11]July 7, 2021

Mimikatz creator Benjamin Delpy, who is also responsible for the R&D Security Center at the Banque de France, shared a screenshot of a reversed-engineered Windows DLL with The Register and explained that the problem was down to how Microsoft was checking for remote libraries in its patch for PrintNightmare aka CVE-2021-34527.

[12]Microsoft patches PrintNightmare – even on Windows 7 – but the terror isn't over

[13]The PrintNightmare continues: Microsoft confirms presence of vulnerable code in all versions of Windows

[14]PrintNightmare: Kicking users from Pre-Windows 2000 legacy group may thwart domain controller exploitation

[15]Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller

"To determine if the library is remote or not," he told us, "Microsoft check if the filename start by \\, like in \\remoteserver\sharename\filename"

"But in fact, the is another filename convention that can be used for remote file like: \??\UNC\remoteserver\sharename\filename"

[16]

[17]

Delpy described the issue as "weird from Microsoft" and was blunt about how the fix made it out in that form, opining that he believed: "They did not test it for real."

To be fair to the Windows giant, we can imagine there was a good deal of consternation within its walls after the accidental disclosure of the PrintNightmare vulnerability. We asked Microsoft for its take on Delpy's findings, and Redmond is stone-walling.

[18]

PrintNightmare has proven to be, frankly, a nightmare for the IT giant's customers. Turning off the print spooler service on domain controllers and systems that do not print is the official [19]guidance from Uncle Sam. Microsoft says about the same, and to install patches, with more [20]info here .

In short, disable the vulnerable the print spooler service on your Windows systems to prevent exploitation.

This leaves networks with little choice. We've heard that the University of Reading in the UK, for one, pushed out a memo that [21]read : "Please be advised that we have taken the difficult decision to disable all printing on the University's network, and from UoR devices printing at home."

[22]

"This renders all printing at the university, including locally connected USB printers, unusable," observed the Register reader who forwarded on the update to us. "Not without its problems."

The university has since begun pushing the patch out to PCs on its network. It may find itself having to push out a patch to patch the patch, [23]in true Microsoft style. ®

Get our [24]Tech Resources



[1] https://msrc-blog.microsoft.com/2021/07/06/out-of-band-oob-security-update-available-for-cve-2021-34527/

[2] https://www.theregister.com/2021/07/07/printnightmare_patched/

[3] https://twitter.com/wdormann/status/1412752904822345728

[4] https://twitter.com/GossiTheDog/status/1412533634851082253

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YOYkAWUrq4Nks@76DHsJ5gAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dtyp/62e862f4-2a51-452e-8eeb-dc4ff5ee33cc

[7] https://twitter.com/hashtag/mimikatz?src=hash&ref_src=twsrc%5Etfw

[8] https://twitter.com/hashtag/printnightmare?src=hash&ref_src=twsrc%5Etfw

[9] https://t.co/Wzb5GAfWfd

[10] https://t.co/HTDf004N7r

[11] https://twitter.com/gentilkiwi/status/1412771368534528001?ref_src=twsrc%5Etfw

[12] https://www.theregister.com/2021/07/07/printnightmare_patched/

[13] https://www.theregister.com/2021/07/02/printnightmare_cve/

[14] https://www.theregister.com/2021/07/01/printnightmare_windows_fix/

[15] https://www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOYkAWUrq4Nks@76DHsJ5gAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOYkAWUrq4Nks@76DHsJ5gAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOYkAWUrq4Nks@76DHsJ5gAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[19] https://us-cert.cisa.gov/ncas/current-activity/2021/06/30/printnightmare-critical-windows-print-spooler-vulnerability

[20] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

[21] https://www.reading.ac.uk/internal/staffportal/news/articles/spsn-858014.aspx

[22] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOYkAWUrq4Nks@76DHsJ5gAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[23] https://www.theregister.com/2021/03/16/microsoft_printer_fix/

[24] https://whitepapers.theregister.com/



Copilot?

elsergiovolador

- What would you want to fix today?

- A print spooler, please

- Here is a selection of open source codes, that look like may fix the issue, sir

- Which one do I choose?

- I suggest you gather your entire team and vote!

- Unfortunately we have a split vote. What should we do?

- Release each one and increase the telemetry. These are quality remixed open source codes, something must work!

- Sure thing, copilot!

(day later)

- Morning copilot! We have listened through telemetry and volume of moans rose by 55% and the current rate of fcks per minute is 15320. Some users also were found swearing and looking for their credit card, they are buying Macs! What do we do!?

- Okay folks. Let me see if I the secret model trained on private repositories is done. Hopefully, we can lift some professional source codes!

...

(of course this is just my imagination and this has not happened)

The patch breaks printing

TReko

We have customers with hundreds of Zebra printers (used in warehouses).

This patch has completely stopped their business.

red03golf

Considering the level of vulnerability of this exploit and the extensiveness of how much control an attacker could easily gain over one's computer, it's imperative to upgrade one's OS; therefore, I upgraded ... to LINUX ... problem solved.

Execute remote DLLs? Seriously?

Bitsminer

This seems, on the face of it, completely stupid.

I seem to recall there was a US DoD STIG that provided a registry edit to disable this; but after a quick search I cannot find it.

Any hints?

American business long ago gave up on demanding that prospective employees
be honest and hardworking. It has even stopped hoping for employees who are
educated enough that they can tell the difference between the men's room and
the women's room without having little pictures on the doors.
-- Dave Barry, "Urine Trouble, Mister"