PrintNightmare, a new Windows Print Spooler vulnerability
On Thursday, July 1, 2021, Microsoft issued a security alert regarding the CVE-2021-34527 vulnerability, known as the "Windows Print Spooler Remote Code Execution Vulnerability" or "PrintNightmare" (official Microsoft bulletin available here). This vulnerability affects the Windows Print Spooler service and allows for remote arbitrary code execution with SYSTEM privileges using a domain account.
What is the Windows Print Spooler service?
The Print Spooler service is an executable file (spoolsv.exe) that runs by default when the operating system starts. This service implements both client and server roles for the printing system. It is responsible for managing print jobs and converting them into printer-specific formats.
This service uses:
- the RPC (Remote Procedure Call) port 135 (TCP);
- dynamic RPC ports, ranging from 49152 to 65535 (TCP), to register RPC endpoints for the MS-PAR printing protocols (Print System Asynchronous Remote Protocol), MS-RPRN (Print System Remote Protocol), MS-PAN (Print System Asynchronous Notification Protocol) (server) and to call the functions of these printing protocols (client);
- port 80 for support of the IPP (Internet Printing Protocol) and MS-WPRN protocols (Web Point-and-Print Protocol) if it has been configured to support IPP;
- SMB ports 139, 445 for file sharing or if the protocols mentioned above are not supported.
What is the PrintNightmare CVE-2021-34527 vulnerability?
The PrintNightmare CVE-2021-34527 vulnerability is related to the driver addition feature on a print server within the MS-RPRN protocol.
When adding a driver to a print server, the client follows these steps:
- The client verifies that it can call the following function via RPC: RpcAddPrinterDriver ;
- The client ensures that the driver files are accessible by the print server;
- The client creates an object containing information about the driver to be installed, specifically the "pDriverPath", "pDataFile", and "pConfigFile" paths;
- The client calls the RpcAddPrinterDriver function, passing the print server name and the object created in the previous step as arguments.
The RpcAddPrinterDriver function copies the files specified in "pDriverPath", "pDataFile", and "pConfigFile" into the C:\Windows\System32\spool\drivers\x64\3\newdirectory, then into the C:\Windows\System32\spool\drivers\x64\3directory. The files corresponding to "pDriverPath" and "pConfigFile" are then loaded.
In its latest version, the Print Spooler service verifies that the paths specified in the "pDriverPath" and "pConfigFile" variables are not in UNC (Universal Naming Convention) format. This prevents the use of network share paths, for example. However, this check is not performed on the "pDataFile" variable.
The first step of the attack is to upload a malicious dynamic library to the C:\Windows\System32\spool\drivers\x64\3directory, using the RpcAddPrinterDriver function. It is sufficient to provide a path in UNC format (e.g., \\Attacker_IP\share\Evil.dll) in the "pDataFile" variable that is accessible by the target machine.
At this point, the malicious library has not yet been loaded by the service.
The second stage of the attack involves calling the RpcAddPrinterDriver function again, this time providing the path to the malicious dynamic library (C:\Windows\System32\spool\drivers\x64\3\Evil.dll), which was uploaded previously, in the "pConfigFile" variable. The expected result of this second call is the loading of the malicious dynamic library.
Unfortunately for the attacker at this stage, this is not the direct result: due to file conflicts (some of the files to be copied already exist in this directory), an error occurs during the file copy process, and the RpcAddPrinterDriver function does not allow the scenario to proceed further.
However, there is a method similar to RpcAddPrinterDriver called RpcAddPrinterDriverEx (documentation available here), which allows for downgrading or updating a driver on a print server. This function takes the same first two arguments as input, as well as a list of options, "dwFileCopyFlags," which allows you to specify how to handle the copying of the driver files to be replaced.
The "APD_COPY_ALL_FILES" option forces the copying of files regardless of their timestamp. This is the option used for the attack. The steps of the attack are then identical to what was described above with the RpcAddPrinterDriver function.
The subtlety of the attack lies in bypassing the authorization check implemented in the RpcAddPrinterDriverEx function. Indeed, calling this method requires the "SeLoadDriverPrivilege" privilege according to Microsoft documentation. This check can be bypassed by providing unexpected values in "dwFileCopyFlags" to the RpcAddPrinterDriverEx function.
According to the source code of the PoC, the combination of the three options "APD_COPY_ALL_FILES," "APD_COPY_FROM_DIRECTORY," and "APD_INSTALL_WARNED_DRIVER" allows for bypassing the authorization check.
The "ValidateObjectAccess" check then verifies if the user has access to the Print Spooler service. However, standard domain users (non-admins) have access to this service if the "Authenticated Users" group is part of the "Pre-Windows 2000 Compatible Access" group, which is the case by default. Thus, it is still necessary to have a valid domain account to carry out the attack.
Which assets are impacted by the CVE-2021-34527 vulnerability?
All versions of Windows contain the vulnerable code and are therefore vulnerable. However, certain conditions must be met to allow for the exploitation of the vulnerability.
Since this attack goes through the Print Spooler, machines are not vulnerable if this service is disabled.
Consequently, Cyberwatch recommends identifying machines with an active Print Spooler service within the information system: if these machines are not equipped with Microsoft security updates (KB5004945, KB5004946, KB5004947, KB5004950, KB5004951, KB5004953, KB5004954, KB5004955, KB5004958, KB5004959), these machines must be considered vulnerable to CVE-2021-34527.
The Cyberwatch platform allows you to easily identify the affected assets in several ways:
- Use our vulnerability scanner to identify assets affected by CVE-2021-34527;
- Use the service:Spooler:Auto query to display assets with the Print Spooler enabled by default in your information system;
- Use the MSDefender-Spooler-Disable compliance rule to identify assets that have the Print Spooler started or enabled by default in your information system;
- Use our system service status reports to visualize assets with the Print Spooler enabled by default.
You can request a demo of our platform today and search for this vulnerability via our contact form.
Domain controllers are specifically targeted by this attack because they remain vulnerable even after applying the June 8, 2021 patch, which notably addresses the CVE-2021-1675 vulnerability.
What is the impact of the PrintNightmare / CVE-2021-34527 vulnerability?
The PrintNightmare vulnerability allows an attacker who has compromised a domain account to escalate their privileges and take full remote control of a domain controller, or execute arbitrary code.
How easy is it to exploit PrintNightmare / CVE-2021-34527?
Several exploits are available for free and publicly on the internet. However, the attack requires having a domain account beforehand.
How can PrintNightmare / CVE-2021-34527 be neutralized?
Microsoft announced a series of out-of-band security patches (outside of Patch Tuesday) on July 6, 2021, at 11:12 PM.
These patches are available under the following references:
- KB5004945 for Windows Server 20H2, Windows Server 2004, Windows 10 20H2, Windows 10 2004, Windows 10 21H1;
- KB5004946 for Windows 10 1909;
- KB5004947 for Windows Server 2019, Windows 10 1809;
- KB5004950 for Windows 10;
- KB5004948 for Windows Server 2016 and Windows 10 1607;
- KB5004951 and KB5004953 for Windows Server 2008 R2 and Windows 7;
- KB5004956 and KB5004960 for Windows Server 2012;
- KB5004954 and KB5004958 for Windows Server 2012 R2 and Windows 8.1;
- KB5004955 and KB5004959 for Windows Server 2008 SP2.
This information is taken from the official Microsoft bulletin, which also recommends disabling the Print Spooler service on machines that do not need to manage printing.
To disable the Print Spooler service, you can use the following PowerShell commands on your domain controller:
Stop-Service -Name Spooler -Force
Set-Service -Name Spooler -StartupType Disabled
It is also possible to limit the attack surface by removing the "Authenticated Users" group from the "Pre-Windows 2000 Compatible Access" group.
Cyberwatch also recommends consulting the bulletin from the National Cybersecurity Agency of France (ANSSI) CERTFR-2021-ALE-014 and scanning your information system for the vulnerability as soon as possible, targeting at least your domain controllers.
Compromise detection rules are also provided by Microsoft.
If, despite the official recommendations, you cannot disable the Print Spooler on your most sensitive machines, Microsoft indicates that, in addition to installing security updates, you should verify the presence of the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint
NoWarningNoElevationOnInstall
NoWarningNoElevationOnUpdate
If these registry keys exist, their value must be set to 0. If these registry keys do not exist, no further action is required after installing the security updates.
Microsoft also offers a second workaround, which involves setting the "Allow print spooler to accept client connections" policy to "Disabled" via Group Policy (GPO). However, applying this setting alone still allows for local attacks on the vulnerable system under certain conditions.
In this context, Cyberwatch recommends disabling the Print Spooler whenever possible to avoid any configuration errors that might leave the vulnerability exposed, and waiting for the release of security patches before re-enabling the service.
Cyberwatch recommends applying the available security updates as soon as possible, prioritizing domain controllers.
In accordance with ANSSI hardening recommendations, Cyberwatch also advises disabling the Print Spooler service on machines that do not require it, particularly on domain controllers.
