Computers & Electronics

PrintNightmare Vulnerability

  • Last Updated:
  • Jul 9th, 2021 7:59 pm
25 replies
Deal Fanatic
User avatar
Jan 16, 2011
7205 posts
9218 upvotes
The NORTH
So severe that they are releasing a patch for Windows 7.
[OP]
Deal Expert
Jun 15, 2011
45063 posts
8129 upvotes
elgros4 wrote: Or just disable the spooler service in the mean time.

In my case it was already disabled on my gaminc pc. I disable all uneeded services and it help protect me agains 0days vulnerability.
For the average Joe / Jane, they may not know this.
Blanka
Deal Fanatic
Sep 16, 2013
7742 posts
5406 upvotes
SW ON
Do you expose your printers to the internet? Don't you have routers? I don't think the average Joe is affected by this.
Deal Fanatic
User avatar
Jan 16, 2011
7205 posts
9218 upvotes
The NORTH
alpovs wrote: Do you expose your printers to the internet? Don't you have routers? I don't think the average Joe is affected by this.
I think your a little off, this vulnerability is with the print spooler in windows allowing a attacker to potentially gain access to your computer. It's not a vulnerability with printers.
Deal Fanatic
Sep 16, 2013
7742 posts
5406 upvotes
SW ON
kr0zet wrote: I think your a little off, this vulnerability is with the print spooler in windows allowing a attacker to potentially gain access to your computer. It's not a vulnerability with printers.
I meant printers connected to Windows computers. They can be shared. If you don't share a printer, how do you expose its spooler to the world especially behind a router?
Deal Fanatic
User avatar
Jan 16, 2011
7205 posts
9218 upvotes
The NORTH
alpovs wrote: I meant printers connected to Windows computers. They can be shared. If you don't share a printer, how do you expose its spooler to the world especially behind a router?
The print spooler is a service that runs as part of the Windows operating system to allow your computer to que print documents. Its on by default and a vulnerability has been found to allow an attacker to potentially access the operating system from that service. It doesn't matter if you have a printer or not, the service is running as part of the operating system.

Run MSCONFIG.EXE and click on the Services tab. Click on the Services column to sort alphabetically and scroll down to Print Spooler. The status will tell you if its running or not but I'm 99% sure that unless you have disabled it then it is on by default.

Attackers can access the service even behind a router by initiating a connection to your computer (via the internet) and accessing the vulnerability.
Deal Fanatic
Sep 16, 2013
7742 posts
5406 upvotes
SW ON
kr0zet wrote: Attackers can access the service even behind a router by initiating a connection to your computer (via the internet) and accessing the vulnerability.
One can't initiate a connection from outside to computers behind the NAT. How can they? If they could this spooler would have been the least of our problems.
Deal Fanatic
User avatar
Jan 16, 2011
7205 posts
9218 upvotes
The NORTH
alpovs wrote: One can't initiate a connection from outside to computers behind the NAT. How can they? If they could this spooler would have been the least of our problems.
There are literally hundreds of ways to initiate a connection to a computer behind a NAT. Maybe you are savvy enough to avoid it but not everyone is.

Besides, if this was a nothingburger do you really think that Microsoft would be releasing an update for Windows 7 years after they officially ended support for the OS?
Microsoft (MSFT) warned that hackers that exploit the vulnerability could install programs, view and delete data or even create new user accounts with full user rights. That gives hackers enough command and control of your PC to do some serious damage.
Windows 10 is not the only version affected -- Windows 7, which Microsoft has ended support for last year, is also subject to the vulnerability.
Despite announcing that it would no longer issue updates for Windows 7, Microsoft issued a patch for its 12-year old operating system, underscoring the severity of the PrintNightmare flaw. Updates for Windows Server 2016, Windows 10, version 1607, and Windows Server 2012 will are "expected soon," it said.
"We recommend that you install these updates immediately," the company said.
If you want to ignore it from behind a NAT, feel free. Just be sure that your router's Firmware is up to date.
Deal Fanatic
Sep 16, 2013
7742 posts
5406 upvotes
SW ON
kr0zet wrote: There are literally hundreds of ways to initiate a connection to a computer behind a NAT. Maybe you are savvy enough to avoid it but not everyone is.

Besides, if this was a nothingburger do you really think that Microsoft would be releasing an update for Windows 7 years after they officially ended support for the OS?



If you want to ignore it from behind a NAT, feel free. Just be sure that your router's Firmware is up to date.
I use pfSense. My "firmware" is up to date.

Please share how to initiate a connection to a computer behind NAT.

If someone could explain how this vulnerability works it would be helpful. It's difficult to find the details.
Deal Expert
User avatar
Apr 16, 2001
16331 posts
3063 upvotes
alpovs wrote: I use pfSense. My "firmware" is up to date.

Please share how to initiate a connection to a computer behind NAT.

If someone could explain how this vulnerability works it would be helpful. It's difficult to find the details.
I think most of the tech sites reporting on don't actually understand it either. I just want to know which ports to close in my firewall, that's all.
Automatic down-votes: Eufy, D-Link, TP-Link, Newegg, Canada Computers, any Chinese-owned cellphone, laptop or IoT device.
Deal Addict
User avatar
Mar 3, 2011
4675 posts
28259 upvotes
You don’t need a printer spooler service, this is more for high volume printing. For now, just disable the service and wait for the patch to be released.
__
Want to know the latest Costco Clearance items and prices in Ontario.. check out my thread here.
Deal Fanatic
Sep 16, 2013
7742 posts
5406 upvotes
SW ON
markopas wrote: You don’t need a printer spooler service, this is more for high volume printing. For now, just disable the service and wait for the patch to be released.
But the patch has been released already.
Deal Addict
User avatar
Mar 3, 2011
4675 posts
28259 upvotes
alpovs wrote: But the patch has been released already.
Ha-Zah!!
__
Want to know the latest Costco Clearance items and prices in Ontario.. check out my thread here.
Member
Feb 9, 2008
408 posts
331 upvotes
Vancouver, BC
This exploit is a big deal to businesses, not home users (limited damage).
The way I understand it is:
Hackers need to already have access to a computer on the network.
Normally, this does not give them access to the servers, as they're limited to whatever the compromised user has access to.
This exploit lets them gain full access (as SYSTEM account) to any Windows machine on the network running the unsecured print spooler.
Full access means they can disable security software, access any files, install ransomware, etc.

For a home user, a family member's computer could spread malware this way.


Also, the patch apparently doesn't fix it...
Deal Addict
User avatar
Feb 12, 2008
4403 posts
299 upvotes
Toronto
zerod wrote: Also, the patch apparently doesn't fix it...
This doesn't surprise me at all. Guess I have to wait a bit to patch the update.
Nothing to see here...keep looking.
[OP]
Deal Expert
Jun 15, 2011
45063 posts
8129 upvotes
zerod wrote: This exploit is a big deal to businesses, not home users (limited damage).
The way I understand it is:
Hackers need to already have access to a computer on the network.
Normally, this does not give them access to the servers, as they're limited to whatever the compromised user has access to.
This exploit lets them gain full access (as SYSTEM account) to any Windows machine on the network running the unsecured print spooler.
Full access means they can disable security software, access any files, install ransomware, etc.

For a home user, a family member's computer could spread malware this way.


Also, the patch apparently doesn't fix it...
Yup. Don't forget VSS too ;)
Blanka

Top