Print server and Print Nightmare update

Manuel Galdamez 121 Reputation points
2021-08-17T16:16:05.733+00:00

Hi All,

I'm having issues with some Print Servers after running Windows Updates and installed

2021-08 Cumulative Update for Windows Server 2019 for x64-based Systems (KB5005030)

After the update installation I'm getting the error "Connect to printer Windows cannot connect to the printer. Operation failed with error 0x0000011b" and the printer fails to install.

Is there any workaround to keep Print Severs up and running?

I cannot permanently remove the August update, because the Print Nightmare update will come again in Sept Cummulative Update.

I also tried to revert the configurations using:
* “Allow Print Spooler to accept client connections” policy
* HKEY_LOCAL_MACHINE \Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint.

Nothing worked. I will appreciate any advice.

Thanks,

Manuel

Windows Server Printing
Windows Server Printing
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Printing: Printer centralized deployment and management, scan and fax resources management, and document services
640 questions
{count} votes

54 answers

Sort by: Most helpful
  1. Alan Morris 1,156 Reputation points
    2021-09-16T21:33:13.127+00:00

    @Joakim c
    I am not expecting Microsoft to be patching Windows 7 with the updated protocol methods but I could be wrong.

    Add the Windows LPD service to the print server

    On the Windows 7 client systems create a local printer using a Standard TCP/IP targeting the IP or hostname of the print server.
    132727-image.png

    The print system issues an SNMP call which will fail to the LPD service on the print server. You will land on this page. Be patient, 60 to 60 seconds. Select Custom
    132857-image.png

    Configure the port as LPR. The Queue Name is the printers Share name. Make it easy on yourself and do NOT have spaces in the share name. You must select LPR Byte Counting Enabled.

    132883-image.png

    Finish adding the printer with the proper driver. When you send the test page, you will see the job owner as "USER (IP of client system)

    This solution should completely bypass the update from yesterday.

    1 person found this answer helpful.
    0 comments No comments

  2. Dan Campbell 1 Reputation point
    2021-08-17T18:21:44.513+00:00

    Manuel,

    We recently experienced this in our environment but have yet to pinpoint the update that might have caused this. Current fix for us is running the below command in elevated command prompt as administrator account on the impacted machine :

    "reg add "HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint" /v RestrictDriverInstallationToAdministrators /t REG_DWORD /d 0 /f"

    My assumption is that a Windows update changed the way that Windows is handling print jobs and is looking at the registry to see if this key exists. If it does not exist it will not allow non admin accounts to install the driver. If it does exist, it must be set to 0 and not 1 for non admins to install.

    Let me know how it goes.

    Dan

    0 comments No comments

  3. Bill V 6 Reputation points
    2021-08-17T22:59:27.353+00:00

    I'm seeing this same behavior Mark, as are a lot of folks. With the patch installed I can't installed a printer from a print server even with local admin privileges via GUI or command line. I don't want to disable the protections provided by this patch but it's my only viable option at this point. I wonder if the users will be prompted for credentials more than once if you use the scheduled task workaround.

    Microsoft, please provide a more workable solution to this vulnerability.


  4. frup 1 Reputation point
    2021-08-19T12:46:53.09+00:00

    We had the problem too and could solve it. We had to use a combination of all mentioned solutions + some parts of: kb5005652

    We had to create a GPO with:

    1. Reg-Key: "RestrictDriverInstallationToAdministrators" = 0
    2. Package Point and PrintApproved servers just list all your printservers (See KB5005652 at the End of the Article) and
    3. Point and Print Restrictions:
      • Users can only point and print to these servers (not checked)
      • Users can only point and print to machines in their forest (checked)
      • When installing drivers for a new connection: Show warning and elevation prompt
      • When updating drivers for an existing connection: Show warning and elevation prompt

    I know the Part 3 does not really match to the other settings but it was just a quick and dirty solution. At the moment the users can print. Please Reply if you have any similar experience.

    BTW: I really don't know if this breaks the PrinterNightmare fix. But our >3.000 customers hat to print again...

    kind regards

    0 comments No comments

  5. sung han 1 Reputation point
    2021-08-20T14:16:41.797+00:00

    I am not the only. lol.
    I just screwed my print server, had to roll back the update. is the registry addition MS' official's?

    0 comments No comments