CTD-000062

AD domain controller with enabled print spooler

Critical
Active Directory
Privilege Escalation
v30

Signature Identity

CTD-000062
Threat ID
30
Version
IOE
Indicator Type

Threat Description

  1. Print spooler is a software service that manages printing processes. The spooler accepts print jobs from computers and makes sure that printer resources are available. The spooler also schedules the order in which print jobs are sent to the print queue for printing.
  2. While seemingly harmless, any authenticated user can remotely connect to a domain controllers print spooler service, and request an update on new print jobs. Also, users can tell the domain controller to send the notification to the system with unconstrained delegation. These actions test the connection and expose the domain controller computer account credential (Print spooler is owned by SYSTEM).
    Due to the possibility for exposure, domain controllers and Active Directory admin systems need to have the Print spooler service stopped and disabled. The recommended way to do this is using a Group Policy Object (GPO).

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

How to stop and disable Print Spooler Service:

  1. Press the Windows Key + R.
  2. Type in services.msc.
  3. Press Enter.
  4. Double-click on Print Spooler.
  5. Click on the Startup type drop-down menu.
  6. Chose Disabled.
  7. Click on Stop.
  8. Click on Apply.

Frequently Asked Questions

What does AD domain controller with enabled print spooler mean?

The Print Spooler service is running on the Active Directory environment's domain controllers, allowing any authenticated user to remotely connect and request updates on new print jobs, potentially exposing the domain controller's computer account credential.

This vulnerability enables attackers to remotely connect and expose domain credentials, allowing them to compromise the domain controller or other systems within the Active Directory environment through Kerberos authentication attacks or lateral movement. The exposed credential can be used for further compromise through Kerberos ticket manipulation or other identity-based attacks.

Attackers can use the exposed Print Spooler service to test connections and obtain the domain controller's computer account credential, which can be used for further compromise through Kerberos ticket manipulation or other identity-based attacks. This allows attackers to gain access to sensitive information and potentially move laterally within the Active Directory environment.

Cayosoft Guardian continuously monitors the state of the Print Spooler service across Active Directory environment domain controllers, flagging it as a security issue when found running.

Cayosoft Guardian alerts administrators to disable the Print Spooler service using Group Policy Objects (GPOs), preventing remote connections and exposure of domain credentials, thus reducing the potential for compromise. This helps provide visibility into security issues and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical