What's new

News PrintNightmare (CVE-2021-34527)

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Wallace_n_Gromit

Senior Member
July 8. 2021 UPDATE:

Microsoft’s emergency patch fails to fix critical “PrintNightmare” vulnerability​


Note: The article does make this point: "...Despite Tuesday’s out-of-band patch being incomplete, it still provides meaningful protection against many types of attacks that exploit the print spooler vulnerability. So far, there are no known cases of researchers saying it puts systems at risk. Unless that changes, Windows users should install both the patch from June and Tuesday and await further instructions from Microsoft..."

July 6, 2021 UPDATE:

Windows 10 KB5004945 emergency update released to fix PrintNightmare​


July 2, 2021 Original Post:



I typically disable some running services that I rarely use as a matter of habit at boot up--so I always see the displayed services on my taskbar (such as [Safely Remove Hardware and Eject Media], [Windows Security - No actions needed], [Epson Event Manager], [NordVPNapp], etc., etc. << I don't remove those.

So, several days ago (I don't recall if I left the computer on overnight or booted up) I see a new service icon that refers to Fax (I didn't write it down, or take a pic but had never seen it before). I believe I disabled it and haven't seen it since.

TODAY, with word of this "PrintNightmare" vulnerability, I am a bit concerned.

I disabled Fax and Print Spooler service(s) which were both enabled per the article's recommendation a few minutes ago.

As of this moment, I am running Malwarebytes and a Windows Defender quick scan. I will soon do a Windows Defender full scan, then a Windows Defender Offline scan.

Can anyone offer a comment/recommendation/idea/thought?

ADD: Malwarebytes shows no threat. Windows Defender quick scan shows one threat (though can't figure out how to see it). Windows Defender Offline scan is done - no message(s). Running Windows Defender full scan now.

I do recall that the other day Windows Defender full scan did ID a (potential) threat called "EProjManager.exe". Looking for info on this online found that a file with that name is ID'ed as an Epson Printer file. I allowed Defender to get rid of it. I just used [File Manager} to do a search for a file with that name for possible submission to Virus Total. Can't find it.

ADD #2: I'm uninstalling all my Epson programs/files/drivers. If they offered it, I installed it, including that program that allows web side printing. What a crazy thing to do, eh? (in my defense I did that long before I joined this user group and had long forgotten I had done that)
 
Last edited:
So this a printer spooler bug. So your LAN and/or PC must already have been compromised for a miscreant to try and exploit it.
 
So this a printer spooler bug. So your LAN and/or PC must already have been compromised for a miscreant to try and exploit it.
I suppose it's a bad practice in general to load/install too many "features" on too many programs. I would imagine that your threat/vulnerability landscape is greatly enlarged.

This has given me the opportunity to review installed programs on my computer/determine whether I ever use them anymore/and zap them accordingly (like Folding@home which I haven't used in years.)

Doesn't offer a solution if you are correct that my PC was already compromised, but maybe mitigate/offer less opportunity for a miscreant (if he's there) to leverage new vulnerabilities for greater penetration/capabilities.
 
Last edited:

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top