Windows Print Spooler Remote Code Execution Vulnerability

Page 2 of 7 FirstFirst 1234 ... LastLast

  1. Posts : 9,790
    Mac OS Catalina
       #10

    This exploit only affects Domain Controllers not workstations. I am not worried about it because our Windows workstation rarely gets used and in no way is not a Windows Server Edition or behaves as a DC. Workaround for the Windows Print Spooler Remote Code Execution Vulnerability - gHacks Tech News

    Stopping the Spooler service means jobs are going to sit on the machine until you physically go into the folder to purge them out.
      My Computer


  2. WXC
    Posts : 13,170
    Windows 10 Pro 64-bit 22H2 19045.4046
       #11

    bro67 said:
    This exploit only affects Domain Controllers not workstations. I am not worried about it because our Windows workstation rarely gets used and in no way is not a Windows Server Edition or behaves as a DC. Workaround for the Windows Print Spooler Remote Code Execution Vulnerability - gHacks Tech News

    Stopping the Spooler service means jobs are going to sit on the machine until you physically go into the folder to purge them out.

    Thank you , sir.

    This post answered a question, I had logged back in, to pose.

    In my situation, there was no need to 'Disable', this, apparently.

    My ignorance. No other excuse.

    Just wanted to take measures to be secure.

    - - - Updated - - -

    bro67 said:
    This exploit only affects Domain Controllers not workstations. I am not worried about it because our Windows workstation rarely gets used and in no way is not a Windows Server Edition or behaves as a DC. Workaround for the Windows Print Spooler Remote Code Execution Vulnerability - gHacks Tech News

    Stopping the Spooler service means jobs are going to sit on the machine until you physically go into the folder to purge them out.
    WXC said:
    Thank you , sir.

    This post answered a question, I had logged back in, to pose.

    In my situation, there was no need to 'Disable', this, apparently.

    My ignorance. No other excuse.

    Just wanted to take measures to be secure.

    @bro67

    Should I go back into Group Editor, and set this back from 'Disabled', to 'Not Configured'? or simply, leave it be?


    Single desktop PC, hardwired behind router (no wifi). Have a USB connected printer, but never use it. System specs up to date.

    Apologies for bothering you.

    ~~~~~

    I welcome anyone else to answer, as well.

    Thank you.
      My Computer


  3. Posts : 9,790
    Mac OS Catalina
       #12

    I would leave it be, make sure your firewall on the computer and router are not wide open, machine is up to date. You do not leave your front door open or keys in your car do you? Why should you let someone take the chance to find a machine that they can get into and dig around.
    Only 5.5% of all vulnerabilities are ever exploited in the wild | ZDNet
    Top 10 Routinely Exploited Vulnerabilities | CISA

    I onoy use a iPad and iPhone but keep them up to date, even with the Windows machine it is kept up to date. Those who never update or delay updates are just placing theirselves at risk.

    In this case I funnel all emails through Microsoft’s Azure Exchange server with a Security rule in place to check
    for possible phish and malware type emails. https:://krebsonsecurity.com/2021/03/at-least-30000-u-s-organizations-newly-hacked-via-holes-in-microsofts-email-software/

    Have I done some sketchy stuff on a computer, yes in attempts to try and break the OS. Have I learned from doing so, yes I have learned a lot inmbetter security practices.
      My Computer


  4. WXC
    Posts : 13,170
    Windows 10 Pro 64-bit 22H2 19045.4046
       #13

    bro67 said:
    I would leave it be, make sure your firewall on the computer and router are not wide open, machine is up to date.

    Thank you, @bro67.

    I appreciate your detailed reply.

    I'll leave it be, as you suggest. Everything else is good to go.

    Best regards.
      My Computer


  5. Posts : 21,421
    19044.1586 - 21H2 Pro x64
       #14

    A second opinion saying Windows home users don't need to worry about this too much:
    Print Nightmare is going to be a nightmare @ AskWoody

    I've found it most confusing to understand whether home users need to disable to service or not. Disabled it, then decided to re-enable it based on what I read here and the above link.
      My Computer


  6. Posts : 68,953
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #15
      My Computers


  7. WXC
    Posts : 13,170
    Windows 10 Pro 64-bit 22H2 19045.4046
       #16

    steve108 said:
    A second opinion saying Windows home users don't need to worry about this too much:
    Print Nightmare is going to be a nightmare @ AskWoody

    I've found it most confusing to understand whether home users need to disable to service or not. Disabled it, then decided to re-enable it based on what I read here and the above link.

    You're not alone, buddy. I too, found it confusing.

    As for me, I disabled it. No biggie to revert, should I need it in the future.

    Take care.
      My Computer


  8. Posts : 1,938
    Windows 7 Home Premium x64
       #17

    thanks Brink.

    also out-of-band fixes for older Win10 versions are available:

    KB5004946 for Win10 v1909 (build 18363.1646):
    https://support.microsoft.com/help/5004946
    https://www.catalog.update.microsoft...px?q=kb5004946

    KB5004947 for Win10 v1809 LTSC 2019 (build 17763.2029):
    https://support.microsoft.com/help/5004947
    https://www.catalog.update.microsoft...px?q=kb5004947

    KB5004950 for Win10 v1507 LTSB 2015 (build 10240.18969):
    https://support.microsoft.com/help/5004950
    https://www.catalog.update.microsoft...px?q=kb5004950
      My Computers


  9. KCR
    Posts : 355
    Windows 10 Home, 64-bit, Version 22H2 (OS Build 19045.4291)
       #18
      My Computers


  10. Posts : 843
    11 Pro 21H2 (22000.832)
       #19

    Question for youse guys about disabling "Allow print spooler to accept client connections":

    My other computers use my printer on wi-fi in my home LAN. Do you know whether this setting in GP will make it impossible for them to (remotely) print on my printer?

    - - - Updated - - -

    Never mind. In GP at the setting in question, I find this:
    "When the policy is disabled, the spooler will not accept client connections nor allow users to share printers. All printers currently shared will continue to be shared."
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 19:39.
Find Us




Windows 10 Forums