You'll want to shut down the Windows Print Spooler service (yes, again): Another privilege escalation bug found
- Reference: 1626456490
- News link: https://www.theregister.co.uk/2021/07/16/spooler_service_local_privilege_escalation/
- Source link:
The latest Print Spooler service vuln has been assigned [1]CVE-2021-34481 , and can be exploited to [2]elevate privilege to SYSTEM level via file operations.
This can be used by malware already running on a Windows machine or a rogue user to fully compromise a bo
[3]
The solution? For now, you can only "stop and disable the Print Spooler service," disabling both the ability to print locally and remotely. Which is not brilliant news for enterprise nor for all those folk home schooling and printing out work from local printers.
[4]
[5]
Microsoft insisted the latest hole in its print spooler code was distinct from its earlier privilege-escalation and remote-code execution vulnerabilities ( [6]CVE-2021-1675 and CVE-2021-34527 ) and hadn't been introduced by the July security update. It has therefore been lurking for a while, and the IT giant did not immediately confirm which Windows versions were affected.
The engineer credited with uncovering the latest hole in Microsoft's Swiss cheese service was Jacob Baines. Baines, a vulnerability researcher, seemed a little nonplussed at the CVE but said he didn't consider it a variant of PrintNightmare.
If you are here for information on CVE-2021-34481, you'll have to wait for my DEF CON talk. I don't consider it to be a variant of PrintNightmare. The MS advisory/CVE was a surprise to me and, as far as I'm concerned, it wasn't a coordinated disclosure. — Jacob Baines (@Junior_Baines) [7]July 16, 2021
Just a nightmare for admins having to manage printers using the Print Spooler service then.
[8]Microsoft struggles to wake from PrintNightmare: Latest print spooler patch can be bypassed, researchers say
[9]Microsoft patches PrintNightmare – even on Windows 7 – but the terror isn't over
[10]The PrintNightmare continues: Microsoft confirms presence of vulnerable code in all versions of Windows
[11]PrintNightmare: Kicking users from Pre-Windows 2000 legacy group may thwart domain controller exploitation
Baines told The Register that the issue had been disclosed to Microsoft on 18 June. He informed them of a 7 August deadline (for DEF CON).
"They finally confirmed the issue on Monday of this week (July 12)," he said, "and informed me of CVE assignment yesterday (July 15)."
[12]
We'd normally expect a disclosure to happen once there is a patch ready or the issue goes public.
Baines is due to make a [13]presentation at DEF CON entitled "Bring Your Own Print Driver Vulnerability" which promises a talk on how to use vulnerable drivers to escalate one's Windows privileges.
It sounds familiar, and Mimikatz creator Benjamin Delpy joked, when asked for comment by The Register , it "seems a little bit related" to his own findings.
[14]#printnightmare - Episode 3
You know that even patched, with default config (or security enforced with [15]#Microsoft settings), a standard user can load drivers as SYSTEM?
- Local Privilege Escalation - [16]#feature [17]pic.twitter.com/Zdge0okzKi — 🥝 Benjamin Delpy (@gentilkiwi) [18]July 15, 2021
Perhaps.
Baines himself told The Register : "To my knowledge, and Microsoft has not clarified to me otherwise, the specific issue I shared with them isn't a publicly known/used issue. I have not shared the details publicly. I haven't seen anyone else do so either."
[19]
"Of course," he added, "Microsoft knows far more about these printer related issues than I do, and perhaps they are aware of a public disclosure elsewhere. However, they did not share that information with me."
The Reg has asked Microsoft what versions of Windows were affected, when a patch would be available and why it chose to make the disclosure in this way. A Microsoft spokesperson told us the company had nothing further to share beyond the [20]CVE , which does not explain any of that. ®
Get our [21]Tech Resources
[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34481
[2] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34481
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPIBf-GEyvtSAN2hx@IkvwAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPIBf-GEyvtSAN2hx@IkvwAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPIBf-GEyvtSAN2hx@IkvwAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/07/02/printnightmare_cve/
[7] https://twitter.com/Junior_Baines/status/1416020556537794564?ref_src=twsrc%5Etfw
[8] https://www.theregister.com/2021/07/07/printnightmare_fix_fail/
[9] https://www.theregister.com/2021/07/07/printnightmare_patched/
[10] https://www.theregister.com/2021/07/02/printnightmare_cve/
[11] https://www.theregister.com/2021/07/01/printnightmare_windows_fix/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPIBf-GEyvtSAN2hx@IkvwAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://defcon.org/html/defcon-29/dc-29-speakers.html#baines
[14] https://twitter.com/hashtag/printnightmare?src=hash&ref_src=twsrc%5Etfw
[15] https://twitter.com/hashtag/Microsoft?src=hash&ref_src=twsrc%5Etfw
[16] https://twitter.com/hashtag/feature?src=hash&ref_src=twsrc%5Etfw
[17] https://t.co/Zdge0okzKi
[18] https://twitter.com/gentilkiwi/status/1415520478693888004?ref_src=twsrc%5Etfw
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPIBf-GEyvtSAN2hx@IkvwAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[20] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34481
[21] https://whitepapers.theregister.com/
Well businesses (or home) could disable on all pc's with no printer requirement.
In many places that could be a large percentage.
Yes it's not a fix (which as it says is on its way), but it reduces the attack surface.
I mostly use the print function to create pdf files to email to people.
MicroSoft drivers
Give me cause to continue buying pencils and paper.
Wasn't it earlier this week
I was downvoted to **** for saying that it is simply irresponsible to put a print spooler on your domain controller?
If your SMB cannot support separate systems, then your problems go far beyond computers.
Airgap and Sneaker net?
I suppose you can unplug the network, enable spooler, print, disable spooler then plug in network. But no shared printers unless spooler only enabled when only clean trusted PCs on LAN and decent separate firewall?
Spooler on Client...?
Disclaimer: my M$ support days are waaaay behind me.
Does the print client 100% absolutely require the spooler service to be enabled for printing? Or is it possible to have just the driver?
If only the driver is sufficient for filtering then a workaround could be to configure a Linux/CUPS print server with SMB/LDP/IPP.
[I don't believe I'm even thinking about this! What's happened to me?!]
The next update of your virus checker ..
.. will finally do its job and remove Windows itself.
It's the only way.
"For now, you can only "stop and disable the Print Spooler service," disabling both the ability to print locally and remotely."
Thanks, Microsoft, I wouldn't exactly call that a "solution", even a temporary one. It's more like "Shoot yourself in foot to prevent a head injury" type of clause - not being able to print, AT ALL, is rather a deal killer.