News: 1632229209

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Fix network printing or keep Windows secure? Admins would rather disable PrintNightmare patch

(2021/09/21)


Microsoft's Patch Tuesday update last week was meant to fix print vulnerabilities in Windows but also broke network printing for many, with some admins disabling security or removing the patch to get it working.

The problem is complex and first surfaced in January, when Microsoft issued this [1]support note explaining that "a security bypass vulnerability exists in the way the Printer Remote Procedure Call (RPC) binding handles authentication for the remote Winspool interface."

Microsoft's fix was in two phases, first to add a registry setting to increase the authorization level for remote access to printers and second, to inform admins that "the release transitions into the enforcement phase on September 14, 2021. Enforcement phase enforces the changes to address CVE-2021-1678 by increasing the authorization level without having to set the registry value." That September date was "Patch Tuesday" last week – though some admins were already having issues with network printing caused by Microsoft's other mitigation efforts.

[2]

The print nightmare escalated in June when researchers [3]discovered that the print spooler privilege execution vulnerability meant that a compromise of one desktop PC in a network could result in an attacker getting domain administration privileges, since the print spooler runs by default on servers including domain controllers.

[4]

[5]

This [6]discussion on Microsoft's question and answer forum for IT professionals shows the problems administrators now face. "This just hit us this morning too. 9/15/2021. No one can print to the network printers. I removed KB5005613 from our server and rebooted the server and that fixed it," [7]said one such last week – but removing a security patch is not a good solution as it leaves a known vulnerability in place.

[8]Microsoft responds to PrintNightmare by making life that little bit harder for admins

[9]You'll want to shut down the Windows Print Spooler service (yes, again): Another privilege escalation bug found

[10]Microsoft struggles to wake from PrintNightmare: Latest print spooler patch can be bypassed, researchers say

[11]Microsoft patches PrintNightmare – even on Windows 7 – but the terror isn't over

Another [12]found a fix that "worked immediately" – a Group Policy Object (GPO) setting which applies across all targeted computers on a Windows network called RestrictDriverInstallationToAdministrators = 0. Unfortunately, this too undoes the security Microsoft is trying to apply. Setting this is not recommended.

Although Microsoft has published a certain amount of information, it could do more in terms of providing guidance to administrators confronted with security issues on the one hand, and users demanding to be able to print on the other. Others have come up with guidance of their own, including [13]this security post which includes a flowchart to analyse print security in a network.

[14]

Unofficial flowchart for analysing print security on a Windows network

It appears that Microsoft has so far been unable to fix the vulnerabilities in Windows network printing by patching the code and has focused instead on tightening the security around it. A typical Windows network has printers of varying age, from various vendors, with various levels of support. Relevant factors include the way in which network printing is configured, the printer drivers used both on client and server, the version of Windows and its patch level, and the GPOs applied to the PCs.

The type of [15]printer driver called V4 is preferred for security but must be installed on the client. In the case of older versions of Windows such as Windows Server 2008 R2, for which extended support has expired, "customers are required to purchase the Extended Security Update," said Microsoft in the above-mentioned support note. Considering the complexity it is not surprising that some admins have complained of random behaviour.

"I really don't know if this breaks the PrinterNightmare fix. But our >3,000 customers had to print again..." said one admin in the discussion. That is not a good spot to be in and it seems the PrintNightmare saga is not over yet. We have asked Microsoft for further comment and will report back accordingly. ®

Get our [16]Tech Resources



[1] https://support.microsoft.com/en-us/topic/managing-deployment-of-printer-rpc-binding-changes-for-cve-2021-1678-kb4599464-12a69652-30b9-3d61-d9f7-7201623a8b25

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YUoBu4WPNZwciZ@uUWQKlAAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YUoBu4WPNZwciZ@uUWQKlAAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YUoBu4WPNZwciZ@uUWQKlAAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://docs.microsoft.com/en-us/answers/questions/517533/pint-server-and-print-nightmare-update.html

[7] https://docs.microsoft.com/answers/comments/553922/view.html

[8] https://www.theregister.com/2021/08/11/printnightmare_mitigation/

[9] https://www.theregister.com/2021/07/16/spooler_service_local_privilege_escalation/

[10] https://www.theregister.com/2021/07/07/printnightmare_fix_fail/

[11] https://www.theregister.com/2021/07/07/printnightmare_patched/

[12] https://docs.microsoft.com/answers/comments/518963/view.html

[13] https://www.kb.cert.org/vuls/id/383432

[14] https://regmedia.co.uk/2021/09/21/printnightmare.jpg

[15] https://docs.microsoft.com/en-us/windows-hardware/drivers/print/v4-printer-driver

[16] https://whitepapers.theregister.com/



What is affected?

Ilsa Loving

One bit of information that seems to be hard to find is, what is the configuration necessary to allow this to happen?

Specifically, it sounds like this only applies to machines that have shared printing available. Most businesses now have printers with built-in networking capabilities, so there is no reason to be using the shared printer facilities in Windows, and so can (and should) be safely disabled. Am I misunderstanding something?

Re: What is affected?

WolfFan

I’d like this to be more clear, myself. I suspect that network attached printers, including the big floor-standing copier-printer things, should be safe enough, and that setting up Linux or Mac systems to handle other types of print jobs should bypass this, but it’s not clear. I suspect that MS really doesn’t want it to become clear, as that would reveal the dimensions of the fuck-up, and who was completely to blame.

Re: What is affected?

big_D

We use direct network printing (all network printers look after their own print jobs). None of the servers or PCs are set up to share printers. We also install the printers the users require, so no user needs local administration access or administration rights.

That makes management more fragmented, but given that we rarely have any problems or need to re-route printers temporarily, we can get away with it. Which means we can apply the patches and everything keeps working.

Others that rely on central Windows print server have a major problem, on the other hand.

Optimaximal

One issue for us is we still have a small number of clients hanging around on Windows 7 (pending hardware upgrades) and these are unable to receive the January update that allowed for the new encryption MS are using, so basically if you're still a Windows 7 house without Extended Support, you need to apply the registry fix ASAP.

Explains lack of school printing!

Fonant

Ah, so that's why my wife's primary school is unable to print anything out at the moment. Their IT support people said it was a Microsoft problem, but I thought they were joking.

Of course UK schools don't have enough money to buy glue sticks at the moment, so their IT infrastructure is, of course, decades old and held together with sellotape.

Please can we get a new government, that will reverse the Tory cuts? Soon?

Re: Explains lack of school printing!

Boris the Cockroach

Quote:

"Please can we get a new government, that will reverse the Tory cuts? Soon?"

good luck with that as labour will promise funding to outer mongolian duck making habits and make it compulsery that all schools carry a teacher qualified in that.

But no extra funding to sort the IT systems out(and no extra funding for the duck mating habits teacher either)

"Security is our utmost priority", says company after being hit with malware

MiguelC

So, choosing between stopping users from printing or opening their companies to actively used exploits, some admins choose the latter? Or are they forced by management to 'choose' that?

Re: "Security is our utmost priority", says company after being hit with malware

DavidYorkshire

So what would you do in these circumstances? Both options are unacceptable, but you have to choose one!

Anonymous Coward

Why does a printer driver need to have kernel access to operate? Surely it's just a filter that takes in a stream of information (a document) and spits out another stream of information (the likely proprietary bytecode the specific printer model needs). Why isn't it running as 'nobody' with access to two sockets and nothing else? Fucking Windows piece of shit.

Doctor Syntax

"We have asked Microsoft for further comment and will report back accordingly."

Their comment might be unprintable.

jonathan keith

Have all of today's upvotes.

[End of diatribe. We now return you to your regularly scheduled
programming...]
-- Larry Wall in Configure from the perl distribution