Microsoft Windows Print Spooler Remote Code Execution Vulnerability
High CVSS 8.8 Listed in CISA KEV
Summary
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Microsoft:Windows
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2021-34527 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
- http://packetstormsecurity.com/files/167261/Print-Spooler-Remote-DLL-Injection.html Exploit
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34527 Mitigation
- https://www.kb.cert.org/vuls/id/383432 Third Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2021-34527-printnightmare-detection-script Exploit
- https://www.vicarius.io/vsociety/posts/cve-2021-34527-printnightmare-mitigation-script Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34527 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD