Malware Devil

Friday, July 2, 2021

ASB-2021.0123 – ALERT [Win] Microsoft Print Spooler: Multiple vulnerabilities

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256

===========================================================================
AUSCERT Security Bulletin

ASB-2021.0123
Windows Print Spooler Remote Code Execution Vulnerability
2 July 2021

===========================================================================

AusCERT Security Bulletin Summary
———————————

Product: Microsoft Print Spooler
Operating System: Windows
Impact/Access: Administrator Compromise — Existing Account
Execute Arbitrary Code/Commands — Existing Account
Resolution: Mitigation
CVE Names: CVE-2021-34527 CVE-2021-1675
Reference: ASB-2021.0116
ASB-2021.0115

Comment: Vulnerability popularly referred to as PrintNightmare.
POC exploit code has reportedly been released.

OVERVIEW

Microsoft has released an out-of-band critical update to address a
Windows Print Spooler Remote Code Execution Vulnerability.
Microsoft has assigned CVE-2021-34527 to this vulnerability and
acknowledges it has been referred to publicly as PrintNightmare.[1]

This vulnerability has received significant media attention in the past day.
[2] [3] [4] [5]

IMPACT

Microsoft has stated the following:

“Microsoft is aware of and investigating a remote code execution
vulnerability that affects Windows Print Spooler and has assigned
CVE-2021-34527 to this vulnerability. This is an evolving situation
and we will update the CVE as more information is available.

A remote code execution vulnerability exists when the Windows Print
Spooler service improperly performs privileged file operations.
An attacker who successfully exploited this vulnerability could run
arbitrary code with SYSTEM privileges. An attacker could then install
programs; view, change, or delete data; or create new accounts with
full user rights.

An attack must involve an authenticated user calling RpcAddPrinterDriverEx().”
[1]

MITIGATION

Microsoft recommends applying the latest security updates released on June 8
AND determining if the Print Spooler service is running and either disabling it
or disabling inbound remote printing through Group Policy. [1]

Microsoft acknowledges this vulnerability is similar to but distinct from the
recent Print Spooler vulnerability reported as CVE-2021-1675 and addressed by
the June 2021 security updates, and that they are still investigating the issue
and will update the page as more information becomes available. [1]

REFERENCES

[1] Windows Print Spooler Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

[2] ‘PrintNightmare’ Stuxnet-style zero-day
https://www.itnews.com.au/news/researchers-accidentally-publish-printnightmare-stuxnet-style-zero-day-566767

[3] Public Windows PrintNightmare 0-day exploit allows domain takeover
https://www.bleepingcomputer.com/news/security/public-windows-printnightmare-0-day-exploit-allows-domain-takeover/

[4] Researchers accidentally release exploit code for new Windows
‘zero-day’ bug PrintNightmare
https://portswigger.net/daily-swig/researchers-accidentally-release-exploit-code-for-new-windows-zero-day-bug-printnightmare

[5] PrintNightmare, Critical Windows Print Spooler Vulnerability
https://us-cert.cisa.gov/ncas/current-activity/2021/06/30/printnightmare-critical-windows-print-spooler-vulnerability

AusCERT has made every effort to ensure that the information contained
in this document is accurate. However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation’s site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
===========================================================================
—–BEGIN PGP SIGNATURE—–
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYN6fcuNLKJtyKPYoAQh6UA//eRH1nYq6qUaKnuvUnbvR78OWRs0FbaLy
A+yUrt9cljVun2qujErv2XF4JKClaJrwvBg9haLlVcViIt084YjnDpKSf73yhDyw
cDYBrAsmsYa5d9HJTl4rXEHUET4bXQ1C68o7fA9VAbm6WK4uq4RvzwRd5+/12f4G
5bnPxpFTvMyRZ8KsxhUI6IjVsi3bxlz+ZGPYTsM/foGVAAf/prmPPBEUaqiVQxv+
ljRbXZ/5BzxPf+mG9txrmeMBc/cw1t7sZ8Pj5xO3lju8+CNbNjkdIoAAFlna0ayL
cl+6zsjyt+zZ0BtKUoe16ae4i1sJVfqrH6vfW/g0YmCAhMr02LCgCtsy0/i9L8rx
alWuK4eNRCkHt3LrM8NhF7zu4YNDWMxMaiZ96wVh7j7rUQ+FeFSTcc5TkaaduqjR
jvI8paNUUmo/kL73rG59YhZ/1q/Nx233BAirze06ht7aY7xJOSuUR8y6eGAnBk++
juonwpYXsV/EBjxlHVqMC6rv2nSxqdnajeN85W5Ntefutv/zZuFgnQBkXmUl20Or
tCmtKoEu3W0BZvBI/8X+N4UVtKCQYpVJDGHA1yIgKUkrXhkuLG5Wj4rFX1VfZ6Fb
xgsuTPhe8Nc1779dJpYER0bkG+eiXayglGJ0Y95ilf0kAlUer55B/silhtdBg2Wz
oAoUPQ3/3Fs=
=RRT5
—–END PGP SIGNATURE—–

Read More

The post ASB-2021.0123 – ALERT [Win] Microsoft Print Spooler: Multiple vulnerabilities appeared first on Malware Devil.



https://malwaredevil.com/2021/07/02/asb-2021-0123-alert-win-microsoft-print-spooler-multiple-vulnerabilities/?utm_source=rss&utm_medium=rss&utm_campaign=asb-2021-0123-alert-win-microsoft-print-spooler-multiple-vulnerabilities

No comments:

Post a Comment

Barbary Pirates and Russian Cybercrime

In 1801, the United States had a small Navy. Thomas Jefferson deployed almost half that Navy—three frigates and a schooner—to the Barbary C...