PoC exploit accidentally leaks for dangerous Windows PrintNightmare bug

Discussion in 'other security issues & news' started by guest, Jun 30, 2021.

  1. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    They almost never do, though.
     
  2. guest

    guest Guest

    Public print server gives anyone Windows admin privileges
    July 31, 2021
    https://www.bleepingcomputer.com/ne...server-gives-anyone-windows-admin-privileges/
     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Print with LINUX- That takes care of that.
     
  4. guest

    guest Guest

    New Windows PrintNightmare zero-days get free unofficial patch
    August 5, 2021
    https://www.bleepingcomputer.com/ne...ightmare-zero-days-get-free-unofficial-patch/
     
  5. guest

    guest Guest

    Microsoft fixes Windows Print Spooler PrintNightmare vulnerability
    August 10, 2021
    https://www.bleepingcomputer.com/ne...s-print-spooler-printnightmare-vulnerability/
    Microsoft finally fixes PrintNightmare vulnerability with KB5005031 and KB5005033 updates
    August 11, 2021
    https://betanews.com/2021/08/11/microsoft-finally-fixes-printnightmare-vulnerability/
     
    Last edited by a moderator: Aug 11, 2021
  6. guest

    guest Guest

    Microsoft confirms another Windows print spooler zero-day bug
    August 11, 2021
    https://www.bleepingcomputer.com/ne...s-another-windows-print-spooler-zero-day-bug/
     
  7. guest

    guest Guest

    Ransomware gang uses PrintNightmare to breach Windows servers
    August 12, 2021
    https://www.bleepingcomputer.com/ne...ses-printnightmare-to-breach-windows-servers/
     
  8. guest

    guest Guest

    Vice Society Leverages PrintNightmare In Ransomware Attacks
    August 12, 2021
    https://blog.talosintelligence.com/2021/08/vice-society-ransomware-printnightmare.html
     
  9. guest

    guest Guest

    Windows 10 PrintNightmare has been handled irresponsibly by Microsoft, says security expert
    August 13, 2021
    https://www.windowscentral.com/windows-10-printnightmare-handled-irresponsibly-microsoft
     
  10. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Service stopped and disabled.
     
  11. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    as an alternative to disabling the service open with registry editor (txt file saved with reg extension):

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers]
    "RegisterSpoolerRemoteRpcEndPoint"=dword:00000002

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint]
    "NoWarningNoElevationOnInstall "=dword:00000000
    "UpdatePromptSettings"=dword:00000000
    "RestrictDriverInstallationToAdministrators"=dword:00000001
    "RegisterSpoolerRemoteRpcEndPoint"=dword:00000002
     
  12. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Same. I just shut the thing down until they learn to build a secure one. If there is even such a thing possible.
     
  13. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Is there anything to worry about if you don't allow malicious printer drivers to run in the first place?
     
  14. guest

    guest Guest

    Microsoft fixes remaining Windows PrintNightmare vulnerabilities
    September 14, 2021
    https://www.bleepingcomputer.com/ne...ining-windows-printnightmare-vulnerabilities/
     
  15. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    wonderful but this update won't install on like 99% on pcs no matter what,
    installing the cab from DISM command sometimes works
     
  16. guest

    guest Guest

    Microsoft's PrintNightmare patch breaks printing for some... again
    September 18, 2021
    https://www.neowin.net/news/microsofts-printnightmare-patch-breaks-printing-for-some-again/
     
  17. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    They need to stop the lame integrating/INCLUDING and LAZY fix routine and simply release A single fix for ALL Micro O/S units.

    Or better yet. do some real tooth & nails WORK and recode the entire printing feature and THEN release that. They have consistently created features where infiltrator's skills has surpassed their own. An unfortunate distinction that is come home to roost on their O/S and worse yet their customers/users who rely on it.
     
    Last edited: Sep 18, 2021
  18. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    In the meantime : https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.Printing::PointAndPrint_Restrictions_Win7
     
    Last edited: Sep 21, 2021
  19. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    I am wrong, I disabled WMI, never disable WMI for updates,
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.