Junglewise Threat Intelligence

CVE-2021-34527: Microsoft Windows Print Spooler Remote Code Execution Vulnerability

CVE-2021-34527 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server 2012, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

The Windows Print Spooler service improperly performs privileged file operations, leading to a remote code execution vulnerability known as PrintNightmare. An authenticated attacker can exploit this to run arbitrary code with SYSTEM privileges, allowing for full system compromise including data manipulation and account creation.

Affected products

  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Microsoft Windows 10 Version 1607
  • Microsoft Windows Print Spooler service

Timeline

  • 2021-07-06: patched: Microsoft released initial security updates and KB5005010.
  • 2021-07-07: patched: Security updates released for Windows Server 2012, 2016, and Windows 10 v1607.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed

Related threats