4HeadDev Posted October 18, 2021 Posted October 18, 2021 Might be worth referring to: http://www.edugeek.net/forums/windows-10/223374-printing-issues-driver-update-needed.html As this thread covers the whole issue. The October 12th patch also appears to cause the exact same issues mentioned in this thread. You can try some of the fixes mentioned in this thread to get it working. A permanent fix that does not comprimise security is to upgrade to 21H1 though.
Michael Posted October 18, 2021 Posted October 18, 2021 As I wrote previously, Server 2016 all running September CU and my test VM running October CU - printers all deploying fine on LTSB16 and LTSC19.
Koldov Posted October 18, 2021 Author Posted October 18, 2021 (edited) Unfortunately I had read that thread (and posted in it) at the time and had implemented most of the workarounds such as Point and Print and the regedit... However, that thread is a bit long now and nobody had posted to it after the October update. Also the issues presented very, very differently so I'm not convinced it is the same. We had print jobs stuck spooling calling themselves 'low-level document' and MS Office crashing (not really complaining about having no printers or drivers, or asking for any admin permissions to reinstall anything)... The answer for some seems to be replacing files in system32, which certainly doesn't appear to be the same problem or have the same workaround/resolution as the original 'print nightmare' . As mentioned in another forum: https://www.bleepingcomputer.com/forums/t/759880/kb5006670-network-printer-problems-again-this-month/ Edited October 18, 2021 by Koldov
2097 Posted October 18, 2021 Posted October 18, 2021 i installed the latest 21h2 on a single machine, none of the printers mapped. I assumed it was a incompatibility issue with PrinterMapper software. But it was an update. https://support.microsoft.com/en-gb/topic/kb5005652-manage-new-point-and-print-default-driver-installation-behavior-cve-2021-34481-873642bf-2634-49c5-a23b-6d8e9a302872 Have you tried that ?
Duke5A Posted October 18, 2021 Posted October 18, 2021 (edited) I goofed. The print server is 2016, sorry for the confusion. The first post the server was at September and by the second post I had updated it to October. I tested a number of clients at both the September and October patch levels against the server first with September on it, and last with October - didn't notice any issues. So, tested clients at higher levels than the sever, the server at higher level than the client and finally both at the same patch level. Everything past the September update seems to be behaving itself. It takes about three or four days for the entirety of the laptop fleet to come up to the latest patch level. I couldn't work out from the other posts where your servers and clients ended up in terms of CU? Here you have clients on (LTSC) with October CU and server (2019) at September CU... Here you have clients (LTSC) on September CU and server (2016) on October CU... I think you have at least established the October CU for the server might not be the problem. But I started this thread because my clients (LTSC and now LTSB) had updated to the October CU and that had broken printing, the server (2012R2) is still on August (just to complicate matters - because I was trying to avoid this MS chaos)... Do you have any clients (LTSC) on October CU? EDIT: At least it gives me the confidence to get the server up to the October CU! Edited October 18, 2021 by Duke5A 1
Koldov Posted October 18, 2021 Author Posted October 18, 2021 (edited) @Duke5A What are you doing in terms of workarounds? Point and Print..? regedit - nonadministratorinstall..? regedit - privacyenabled..? Driver installs to the machine..? PS (or other) scripts..? Dancing naked around a burning pile of computers praying to MS..? EDIT: How are your printers deployed GPO/GPP/other..? Edited October 18, 2021 by Koldov
kingoranks Posted October 18, 2021 Posted October 18, 2021 Every environment is different, I just followed papercut solution. - - - Updated - - - Every environment is different, I just followed papercut solution. https://www.papercut.com/support/known-issues/#ng
DavR Posted October 18, 2021 Posted October 18, 2021 This seems to have struck us too. We were getting away with just the Point & Print group policy settings through September, but now that we've had the October CU, we can't add the photocopiers via GP to machines the user hasn't logged on to before. If I use the RestrictDriverInstallationToAdministrators hack, it starts working again. I think the muted response to this is because a lot of people have already addressed it (either using the reg hack or otherwise) or it's only hitting some print drivers (this one only seems to be hitting Ricoh drivers for us, the HP Universal is fine). Another variable for us is that it only seems to be new logons to new computers - if the user already had their profile cached on a machine pre-update, then it didn't cause them any issues. So given that, by this point in the year, that's most users for us, it's probably masking the problem a certain amount.
Koldov Posted October 19, 2021 Author Posted October 19, 2021 (edited) @DaveAshworth - Yeah, some good points there! I think it isn't as related to the original Print Nightmare as much as everybody is assuming... for us (and a few others around the web), although it might be part of something MS has 'fixed'. I can get printers installed, so all that part of the workaround is working fine but when I actually print... Office applications hang, the job doesn't get to the printer and just stays on spooling... I think I noticed on my machine first though (cached log-in, all printer drivers installed etc) so it may well have been Kyocera drivers as one of my users had said she printed the day after the update, but to a Brother printer... they only noticed the issue when trying to print the day after that to our Kyocera MFD. My testing is on fresh VMs obviously (so the lack of cached log-in might still be a thing) and I've done a few variations of server and client with different CUs and workarounds getting either cannot 'connect to printer' then '0x0000011b' and '0x000006be' but when I've worked around those October on either just kills it... Yes of course most people have got some kind of workaround, but there are so many now it's hard to pin down who's using what! Everybody has something in place, be it variations of reg hacks, type-4 drivers, point and print, drivers pre-installed on the image, printing directly or various scripts. Then there are all the different client and server OS versions everybody is using... and the fact that a lot of people just aren't installing the latest CUs... The only thing I've read is that it affects certain files and replacing them with pre CU versions fixes it (it also seems to relate to which file a particular manufacturer uses) as mentioned in another thread (but at least it is some small comfort that other people are seeing this and I'm not going mad): "So our newest fix for KB5006670 is to swap out win32spl.dll, spoolsv.exe and localspl.dll with the ones dates 9\21\2021 ver 10.0.19041.1237" Source: https://www.bleepingcomputer.com/forums/t/759880/kb5006670-network-printer-problems-again-this-month/ A lot of people there saying previous workarounds don't make any difference to this issue... Edited October 19, 2021 by Koldov
DavR Posted October 19, 2021 Posted October 19, 2021 @Koldov, reading this thread again today (with less of an air of panic than I had yesterday!) it does look like you're suffering quite a specific printing mishap with this latest CU. I would agree that it looks like the October CU on workstations, interacting mainly with your Kyocera drivers, that is causing your new weird behaviour. I don't suppose there's any alternative drivers for these devices you can use? Our experience does seem to be driver specific also, I guess depending on how certain drivers interact with the updated print spooler. On my test VM that is updated to October CU, I can make a new printer connection using the HP Universal Driver, for instance, but cannot make a new connection with our Ricoh drivers, it just errors out with "Operation Failed 0x0000139f". This is despite the fact that all necessary drivers are already installed. Luckily, at least for us, all existing connections continue to print OK. I would experiment with different drivers for your Kyoceras as a first option, see if you can find anything that plays nicely with the latest updates.
TwistedHelixis Posted October 19, 2021 Posted October 19, 2021 I needed the server and clients to be on the oct update for things to work. If the server was on the new update but the client was on an older update we had issues, we also had issues with clients being on the new update but the server not.
Koldov Posted October 19, 2021 Author Posted October 19, 2021 Well, feeling pretty lonely on this one... Server 2012R2 (October CU) - Client LTSB & LTSC (October CU) - Point and Print + regedits... Anyway, here's the result of testing so far: Kyocera 1 (Type 3 Universal Driver - Packaged) - Windows cannot connect to the printer - 0x000006be Kyovera 2 (Type 3 Universal Driver - Packaged) - Windows cannot connect to the printer - 0x000006be Ricoh (Type 3 Universal Driver - Packaged) - Windows cannot connect to the printer - 0x0000006 Brother 1 (Type 3 Model Specific - Not Packaged) - Windows cannot connect to the printer - "a policy enabled on your computer blocks NT 4.0 drivers"... WHAT? I can't find one! Brother 2 (Type 3 Model Specific - Not Packaged) - Installs OK Brother 3 (Type 3 Model Specific - Not Packaged) - Installs OK Interestingly it lists the Kyocera & Ricoh printers as having a Print Processor of 'winprint' but the Brother printers don't have one listed (kernel mode\NT 4.0?). Anyway, event viewer is slowly filling up with spoolsv.exe errors, seems to be a certain file - KMUU727V.DLL, then the print spooler terminates, but only with the Kyocera, not the Ricoh or Brother. So this does prove that the original workarounds (Point and Print, regedits) are working as expected and nothing has changed there... it is a new problem. Unfortunately some of the printers are so old they don't have updated drivers (only generic), but I'll give it a go... 1
ThatBoringBloke Posted October 19, 2021 Posted October 19, 2021 You're not alone. I'm having simillar issues, just haven't managed yet to fully put together a work flow of what is and what isn't working. Issues only started happening since Oct Update on 2016 Servers and 1809 LTSC clients. I'll come back to it tomorrow... 1
Koldov Posted October 19, 2021 Author Posted October 19, 2021 Well, I don't know what to say... Just finished a bit of preliminary testing on my fresh VMs (Point and Print and both regedits enabled). Server 2012R2 without October CU Client LTSC without October CU = printing Server 2012R2 without October CU Client LTSC with October CU = no printing (different error on installing printers and 'LocalDownlevelDocument' on printing with a currently installed printer) Server 2012R2 with October CU Client LTSC without October CU = printing Server 2012R2 with October CU Client LTSC with October CU = No printing So, either client or both fully up to date = no printing..? I'm starting to get a bit confused installing and uninstalling all the various updates/drivers/printers..... (time to go home).... Not sure how others seem to be having no problems, but could well be a driver version (tried the latest Kyocera but no joy)....
Duke5A Posted October 19, 2021 Posted October 19, 2021 @Duke5A What are you doing in terms of workarounds? Point and Print..? regedit - nonadministratorinstall..? regedit - privacyenabled..? Driver installs to the machine..? PS (or other) scripts..? Dancing naked around a burning pile of computers praying to MS..? EDIT: How are your printers deployed GPO/GPP/other..? Haven't needed to get naked yet during those rituals, but haven't ruled it out if the need arises. I'm using GPP in one policy to hand out printers at the user level. Then a second policy with Point and Print setup with the mitigations recommended by MS and the registry key to allow non-admin users to install print drivers at the computer level.
PaperCutterBrenda Posted October 20, 2021 Posted October 20, 2021 (edited) Hi there all! Our recommendation to PaperCut customers is to run Mobility Print on their print server. With Mobility Print you share a link to your users and they follow a few steps to get up and running. Mobility Print is free to download and use: https://www.papercut.com/products/free-software/mobility-print/ If you have a managed environment, and you want to deploy printers to users without them having to follow any steps, then you can use Print Deploy to push out the Mobility Print printers. You can also push custom drivers with Print Deploy. Print Deploy is part of PaperCut NG/MF. https://www.papercut.com/products/do-more/print-deploy/ Out of the box you can deploy an unlimited amount of printers to an unlimited amount of users. If you want to configure multiple zones, then there is an additional license cost. You can also choose to use Print Deploy to push out Serverless Printers. So where users print directly to printers without a print server. Edited October 20, 2021 by PaperCutterBrenda
Koldov Posted October 21, 2021 Author Posted October 21, 2021 Also just to catch people who are on this thread but not the other couple on similar topics... Of those who are having problems and previous workarounds not helping with this particular issue, could you tell me if you have this (or similar) set in your domain?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now