Here we go again, a new PoC is in the wild and it’s attacking your print spooler!!
The lastest update from Microsoft does not patch this and even Windows 7 to Windows 2019 is vulnerable.
Mitigation:
Stop the spooler on all devices not needing it, especially DC’s!
Restrict access to print servers with firewall rules.
Run theese commands in your RMM or logon scripts.
Command prompt: net stop spooler && sc config spooler start=disabled
PowerShell prompt: Stop-Service -Name Spooler -Force Set-Service -Name Spooler -StartupType Disabled
Source:
PrintNightmare, Critical Windows Print Spooler Vulnerability | CISA