PT-2021-3528 · Microsoft · Windows Print Spooler+1
Edwardzpeng
+4
·
Published
2021-06-28
·
Updated
2026-04-30
·
CVE-2021-34527
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Print Spooler (affected versions not specified)
Description
The Windows Print Spooler service contains a flaw in how it handles file operations, potentially allowing a remote attacker to execute arbitrary code with SYSTEM privileges. This issue, also known as PrintNightmare, has been actively exploited. Reports indicate that attackers have leveraged this vulnerability to deploy ransomware within networks. The vulnerability is related to improper access control restrictions. While the initial exploitation may require some level of prior access, the vulnerability allows for significant system compromise. The vulnerability affects systems even after applying previous fixes, highlighting the need for continued vigilance. Tools have been developed to scan for vulnerable systems and to help mitigate the exploit, including scripts to restrict Point and Print and Remote Print functionality, and validation for User Account Control (UAC) being enabled.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Print Spooler