HP Printer

Print Spooler – “PrintNightmare” Vulnerability

Microsoft has acknowledged a new remote code execution vulnerability in all versions of Windows that directly affects the print spooler service. The vulnerability is known as “PrintNightmare” and has been assigned CVE-2021-34527.

What is the print spooler service?

The print spooler is a software program inside the Windows operating system responsible for managing all print jobs that get sent via the computer to a print server or directly to the printer. The spooler service gives the user the ability to manage all jobs currently in the queue.

The Risk

If an attacker were to exploit this vulnerability successfully, they would have the ability to run code on your device with SYSTEM level privileges. This would allow the attacker to install programs, view, change or delete data. They could also go as far as to create a new administrative user account on the system.

The Fix

At present, Microsoft has not yet released an update to mitigate this vulnerability. But have instead advised implement the below workarounds to protect your system in the interim.

The Workaround

Disable Print Spooler Service

  1. Open Start
  2. Search PowerShell right-click and select Run as administrator
  3. Type the following command to stop the Print Spooler Service – Net Stop Spooler
  4. Type the following to disable the service – Set-Service -Name Spooler -StartupType Disabled

Once you have completed these steps, your device will be protected against the PrintNightmare vulnerability.

Re-enable Print Spooler Service

If you need to print, you will first need to follow these steps and repeat the previous steps to remain protected. You can also run these once Microsoft has released an update to mitigate the vulnerability. 

  1. Open Start
  2. Search PowerShell right-click and select Run as administrator
  3. Type the following to allow the service to start on a reboot automatically – Set-Service -Name Spooler -StartupType Automatic
  4. Type the following command to start the Spooler service – Net Start Spooler

If you are concerned please contact us for free assistance in ensuring your system is protected

You may also like...

Popular Posts