New
#1
And people wonder, what is the point of disabling services that are not even being used.
Print Spooler vulnerability repeats every 2-3 years and if do not have a printer, it is easy.
Clarified Guidance CVE-2021-34527 Windows Print Spooler VulnerabilityUPDATE 7/8:
Microsoft is aware of and investigating a remote code execution vulnerability that affects Windows Print Spooler and has assigned CVE-2021-34527 to this vulnerability. This is an evolving situation and we will update the CVE as more information is available.
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
An attack must involve an authenticated user calling RpcAddPrinterDriverEx().
Please ensure that you have applied the security updates released on June 8, 2021, and see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability.
Read more:
UPDATE FIX: KB5004945 Windows 10 2004 19041.1083, 20H2 19042.1083, 21H1 19043.1083
And people wonder, what is the point of disabling services that are not even being used.
Print Spooler vulnerability repeats every 2-3 years and if do not have a printer, it is easy.
I have just read about it and it seems to be a very serious and urgent issue until, of course, fixed by MS:
https://www.askvg.com/security-alert...ce-in-windows/
Microsoft suggested disabling the Windows Print Spooler service or at least inbound remote printing through Group Policy.
Microsoft provides further mitigations for PrintNightmare exploit, awards it "high" severity - Windows 10 How to Tutorials
I have thePrint Spooler Service
Disabled
.
On the VERY RARE occasions that I do need toService
toDemand
[ Manual ],Disable
it again.
Set toDisable
:
Code:sc stop Spooler & sc config Spooler start=disabled
Set toDemand
[ Manual ]:
Code:sc start Spooler & sc config Spooler start=demand
I hope this helps.