{"vuid":"VU#914617","idnumber":"914617","name":"Microsoft Windows Print Spooler service fails to properly handle RPC requests","keywords":["Microsoft Windows Print Spooler","DoS","denial of service","RpcGetPrinterData( )","RPC requests","spoolsv.exe"],"overview":"The Microsoft Windows Print Spooler fails to properly handle malformed RPC requests. This vulnerability may allow a remote attacker to cause a denial-of-service condition.","clean_desc":"The Microsoft Print Spooler service manages printing operations on a system. The Print Spooler service fails to properly handle malformed RPC requests. This vulnerability can be triggered by sending a specially crafted RPC request to a vulnerable system. Note that exploit code for this vulnerability is publicly available.","impact":"A remote, unauthenticated attacker could consume large amounts of system resources on an affected device, thereby creating a denial of service.","resolution":"We are unaware of a solution to this problem. Until a solution becomes available the following workarounds are strongly encouraged:","workarounds":"Disable the Print Spooler service Disabling the Print Spooler service will mitigate this vulnerability. To disable the Print Spooler service: 1. Click Start, and then click Control Panel. Alternatively, point to Settings, and then click Control Panel. 2. Double-click Administrative Tools. 3. Double-click Services. 4. Double-click Print Spooler. 5. In the Startup type list, click Disabled. 6. Click Stop, and then click OK. Note that disabling or removing the Print Spooler service on a system will prevent that system from being able to print either locally or remotely. Block or Restrict Access The Print Spooler service is accessible via RPC. Blocking access to RPC services (135/tcp, 139/tcp, 445/tcp) from untrusted networks such as the Internet may mitigate this vulnerability.","sysaffected":"","thanks":"This vulnerability was reported by \nh07.","author":"This document was written by Jeff Gennari.","public":["h","t","t","p",":","/","/","s","e","c","u","n","i","a",".","c","o","m","/","a","d","v","i","s","o","r","i","e","s","/","2","3","1","9","6","/",""],"cveids":[""],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2006-12-04T14:04:58Z","publicdate":"2006-12-04T00:00:00Z","datefirstpublished":"2006-12-05T16:42:41Z","dateupdated":"2006-12-05T20:45:42Z","revision":13,"vrda_d1_directreport":"0","vrda_d1_population":"4","vrda_d1_impact":"3","cam_widelyknown":"20","cam_exploitation":"0","cam_internetinfrastructure":"10","cam_population":"20","cam_impact":"3","cam_easeofexploitation":"14","cam_attackeraccessrequired":"19","cam_scorecurrent":"8.9775","cam_scorecurrentwidelyknown":"8.9775","cam_scorecurrentwidelyknownexploited":"14.9625","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":8.9775,"vulnote":null}