Forum Discussion
Martin Jeppesen
Jul 05, 2021Copper Contributor
PrintNightmare for administrators: Trying to sum up the current knowledge for decision-making:
Hi guys, I wrote this blog post in the hope of making it possible to make decisions on how to mitigate PrintNightmare, while waiting for an official patch from Microsoft. I hope it's useful 🙂 htt...
Martin Jeppesen
Jul 14, 2021Copper Contributor
To be honest, I kind of feel, that Microsoft's statement is a bit of a low blow: "All reports we have investigated have relied on the changing of default registry setting related to Point and Print to an insecure configuration."
They are almost implying, that some customers have "hacked" their systems to an irresponsibly insecure state.
The fact is, that nowhere in the Group Policy help text for this GP setting does it state that the setting - which Microsoft has made available in Group Policy - is frowned upon, is bad security practice or at least explained the ramifications of setting this configuration.
You will even find Microsoft documents online, that will guide you step-by-step on how to set this this insecure configuration.
Also, many enterprises will have printers, that do not have Package Aware printer drivers and have therefore set up this policy in the insecure configuration simply to make things work for their users (and been guided on how to do it through Microsoft documentation).
I do feel, that Microsoft should be willing to take partly responsibility for this instead of just "washing their hands".
They are almost implying, that some customers have "hacked" their systems to an irresponsibly insecure state.
The fact is, that nowhere in the Group Policy help text for this GP setting does it state that the setting - which Microsoft has made available in Group Policy - is frowned upon, is bad security practice or at least explained the ramifications of setting this configuration.
You will even find Microsoft documents online, that will guide you step-by-step on how to set this this insecure configuration.
Also, many enterprises will have printers, that do not have Package Aware printer drivers and have therefore set up this policy in the insecure configuration simply to make things work for their users (and been guided on how to do it through Microsoft documentation).
I do feel, that Microsoft should be willing to take partly responsibility for this instead of just "washing their hands".
Deleted
Jul 14, 2021https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
I think the time will not go back - well, it was revealed!