Executive brief
The Windows Print Spooler service improperly performs privileged file operations, leading to a remote code execution vulnerability known as PrintNightmare. An authenticated attacker can exploit this to run arbitrary code with SYSTEM privileges, allowing for full system compromise including data manipulation and account creation.
Affected products
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
- Microsoft Windows 10 Version 1607
- Microsoft Windows Print Spooler service
Timeline
- 2021-07-06: patched: Microsoft released initial security updates and KB5005010.
- 2021-07-07: patched: Security updates released for Windows Server 2012, 2016, and Windows 10 v1607.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-11-03: disclosed