Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Updates & Insights
  • Questions
  • Learning
    • E-learning Courses
    • Empower Replay: Limited Edition
    • Tutorials
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
      • About the DevOps Program
      • DataMiner DevOps Support
  • Downloads
  • More
    • DataMiner Releases & Updates
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

PrintNightmare 0-day Remote Code Execution exploit

Solved2.53K views1st July 2021RCE security
6
Alex Presland [DevOps Advocate]96 1st July 2021 1 Comment

It has come to light that there is a Remote Code Execution exploit for fully-patched Windows Servers.

A full explanation can be found in the following article:
https://www.bleepingcomputer.com/news/security/public-windows-printnightmare-0-day-exploit-allows-domain-takeover/

Is there any reason why the Print Spooler service cannot be stopped & disabled on a Windows Server running DataMiner?  I don’t think so, but thought that I’d ask.

Ben Vandenberghe [SLC] [DevOps Enabler] Posted new comment 1st July 2021
Ben Vandenberghe [SLC] [DevOps Enabler] commented 1st July 2021

Thanks for sharing that Alex, very useful for the community to be aware of this kind of vulnerabilities.

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
7
Bert Vandenberghe [SLC] [DevOps Enabler]8.29K Posted 1st July 2021 3 Comments

No problem, you can safely disable this service on a DataMiner Agent.

PS: I believe the problem only exists on domain controllers.

PPS: Nice catch! You are very much up to date on security, which is good! We’ve already disabled this on our domain controllers as well!

Bert Vandenberghe [SLC] [DevOps Enabler] Posted new comment 7th July 2021
Alex Presland [DevOps Advocate] commented 2nd July 2021

Thanks for this Bert. Microsoft has now raised https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527 for this issue.

Under the FAQ on this page, it says “The code that contains the vulnerability is in all versions of Windows. We are still investigating whether all versions are exploitable. We will update this CVE when that information is evident.”

We’ve therefore taken the approach of disabling the Print Spooler on all our DataMiner Agent (and other!) Windows Servers.

Bert Vandenberghe [SLC] [DevOps Enabler] commented 2nd July 2021

Thanks for the link! I’ll forward this to our security team!

Bert Vandenberghe [SLC] [DevOps Enabler] commented 7th July 2021

In meantime an emergency patch has been made available by Microsoft. Make sure you install the latest updates!

Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs