4.7.9 (L1) Ensure 'Manage processing of Queue-specific files: Manage processing of Queue-Specific files' is set to 'Enabled: Limit Queue-specific files to Color profiles'

Information

This policy setting manages how queue-specific files are processed during printer installation. At printer installation time, a vendor-supplied installation application can specify a set of files, of any type, to be associated with a particular print queue. The files are downloaded to each client that connects to the print server.

The recommended state for this setting is: Enabled: Limit Queue-specific files to Color profiles

A Windows Print Spooler Remote Code Execution Vulnerability (

CVE-2021-36958

) exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploits this vulnerability could run arbitrary code with SYSTEM privileges and then install programs; view, change, or delete data; or create new accounts with full user rights.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Limit Queue-specific files to Color profiles :

Administrative Templates\Printers\Manage processing of Queue-specific files: Manage processing of Queue-specific files

Impact:

None - this is default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 7e67429400a147410927a835e626e3cdcc538b90990ce435a1ad746f71dd07d7