Windows Print Spooler Remote Code Execution Vulnerability

Page 6 of 7 FirstFirst ... 4567 LastLast

  1. Posts : 5,899
    Win 11 Pro (x64) 22H2
       #50

    Riley7 said:
    KB5004945 did not fix the issue.
    Researchers have bypassed Microsoft's emergency patch for the PrintNightmare vulnerability to achieve remote code execution and local privilege escalation with the official fix installed.

    Microsoft's incomplete PrintNightmare patch fails to fix vulnerability
    Our investigation has shown that the OOB security update is working as designed and is effective against the known printer spooling exploits and other public reports collectively being referred to as PrintNightmare. All reports we have investigated have relied on the changing of default registry setting related to Point and Print to an insecure configuration.
    Source: Clarified Guidance CVE-2021-34527 Windows Print Spooler Vulnerability (4th paragraph)
      My Computers


  2. Posts : 1,490
    Windows 10 Pro x64-bit Build Latest
       #51

    I do not have that registry key in my system either.

    • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint
      My Computer


  3. Posts : 1,938
    Windows 7 Home Premium x64
       #52

    sygnus21 said:
    Do be aware anytime you print - whether printing to paper or to a document such as PDF, you're invoking (using) the Print Spooler. Bottom line is if you "print" you're using the print spooler which is the risk
    it's only a "risk" when there's an active internet connection

    I cut-off my internet connection before printing something to my local HP printer then later re-establish net connection since I only do occasional printing
    no need for me to disable the print spooler service which is a little extreme, imho
      My Computers


  4. Posts : 5,899
    Win 11 Pro (x64) 22H2
       #53

    erpster4 said:
    it's only a "risk" when there's an active internet connection

    I cut-off my internet connection before printing something to my local HP printer then later re-establish net connection since I only do occasional printing
    no need for me to disable the print spooler service which is a little extreme, imho
    This makes not sense. If I'm going to disconnect from the internet I might as well not own a PC.
      My Computers


  5. NMI
    Posts : 1,095
    Windows 11 Pro, Version 22H2
       #54

    erpster4 said:
    it's only a "risk" when there's an active internet connection

    I cut-off my internet connection before printing something to my local HP printer then later re-establish net connection since I only do occasional printing
    no need for me to disable the print spooler service which is a little extreme, imho
    It also doesn't make sense to think that the print spooler service is only available while you're using it.
      My Computer


  6. Posts : 21
    Win 10 Home x64 v. 1903 (Build 18362.1440)
       #55

    erpster4 said:
    thanks Brink.

    also out-of-band fixes for older Win10 versions are available:

    KB5004946 for Win10 v1909 (build 18363.1646):
    https://support.microsoft.com/help/5004946
    https://www.catalog.update.microsoft...px?q=kb5004946

    KB5004947 for Win10 v1809 LTSC 2019 (build 17763.2029):
    https://support.microsoft.com/help/5004947
    https://www.catalog.update.microsoft...px?q=kb5004947

    KB5004950 for Win10 v1507 LTSB 2015 (build 10240.18969):
    https://support.microsoft.com/help/5004950
    https://www.catalog.update.microsoft...px?q=kb5004950

    Thank you for the info on older versions! I have Windows Home version 1903 18362.1441. Which one would work for me?

    - - - Updated - - -

    sygnus21 said:
    I can't say if you're vulnerable or not but installing this July 6 KB5004945 patch you should be safe

    Good luck.
    Thank you.
    Last edited by happyheart; 14 Jul 2021 at 03:18. Reason: Couldn't get quotes to show correctly - like other peoples quotes.
      My Computer


  7. Posts : 9,790
    Mac OS Catalina
       #56

    Anyone still having issues trying to get this to install, use the Powershell update method.
      My Computer


  8. Posts : 21,421
    19044.1586 - 21H2 Pro x64
       #57

    bro67 said:
    Anyone still having issues trying to get this to install, use the Powershell update method.
    If you have installed this 2nd July CU which came out July 13th, then it includes the Print Spooler fix: KB5004237 Windows 10 2004 19041.1110, 20H2 19042.1110, 21H1 19043.1110
      My Computer


  9. T J
    Posts : 60
    10 Home 64-bit 21H2
       #58

    My W10 Home 20H2 desktop installed July Cumulative Updates kb5004945 & kb5004237. Plus I disabled Print Spooler in Services.

    I tried to install Group Policy Editor twice (from majorgeeks website), got install errors twice, said I didn't have adm rights, even though second time I downloaded file and tried to install while logged in as adm. I never saw where you could click on 'run as adm'.

    If CU kb5004237 fixes the problem:
    Do I still need to try to get Group Policy Editor installed in W10 Home? (in order to Disable inbound remote printing)

    thanks
      My Computers


  10. Posts : 21,421
    19044.1586 - 21H2 Pro x64
       #59

    T J said:
    My W10 Home 20H2 desktop installed July Cumulative Updates kb5004945 & kb5004237. Plus I disabled Print Spooler in Services.

    I tried to install Group Policy Editor twice (from majorgeeks website), got install errors twice, said I didn't have adm rights, even though second time I downloaded file and tried to install while logged in as adm. I never saw where you could click on 'run as adm'.

    If CU kb5004237 fixes the problem:
    Do I still need to try to get Group Policy Editor installed in W10 Home? (in order to Disable inbound remote printing)

    thanks
    No, you don't need it if you don't have this key in registry: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 13:28.
Find Us




Windows 10 Forums