You are viewing limited content. For full access, please sign in.

Question

Question

Print Spooler MS Bug

asked on July 8, 2021

Hello,

Customer reached out to us regarding the following notification sent my Microsoft "Windows Print Spooler Remote Code Execution Vulnerability"

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527

They would like to disable all local print services on their LF servers.

Would there be any adverse affects to LF Applications if this is done?

Appreciate the feedback,

Jeff Curtis

0 0

Answer

APPROVED ANSWER SELECTED ANSWER
replied on July 9, 2021

Hi Jeff,

I was wondering when someone would ask about CVE 2021-34527 ("PrintNightmare"). Thanks for bringing it up!

There are no other adverse effects on Laserfiche server applications from disabling Print Spooler that we're aware of aside from the limited exception relating to Laserfiche Snapshot described below. We recommend customers follow Microsoft and CISA guidance to disable the Windows Print Spooler ('spooler') service on all servers that do not need to be running it to address CVE 2021-34527 and reduce attack surface.

Laserfiche Snapshot, being a print driver, has a hard dependency on Spooler. That would only come into play if you had the Snapshot Shared Printer driver installed on a server. If you installed Windows Client with Snapshot on server machines, I advise uninstalling Snapshot prior to disabling Spooler because the Snapshot uninstall process actually fails if Spooler is disabled (it has to de-register the driver).

For end user workstations, Snapshot is a signed printer driver that can only be installed with Administrative rights (enforced via its installer). This information is relevant for Microsoft's PrintNightmare patches and mitigation guidance for machines where disabling Spooler entirely isn't an option.

If remoted into a server with Spooler disabled, you won't be able to print from the web or Windows clients (or anything).

Let me know if you have any follow-up questions.

Cheers,
Sam

8 0
replied on July 9, 2021

Thanks for the information Sam

Jeff Curtis

1 0

Replies

You are not allowed to reply in this post.
You are not allowed to follow up in this post.

Sign in to reply to this post.