Umbra Wiki cve cve/CVE-2021-34527
Back to wiki

CVE-2021-34527 — Microsoft Windows Print Spooler Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2021-34527

CVE-2021-34527: Microsoft Windows Print Spooler Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product Windows
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Known

Description

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

Required action (CISA)

Apply updates per vendor instructions.

Notes

Reference CISA's ED 21-04 (https://www.cisa.gov/news-events/directives/ed-21-04-mitigate-windows-print-spooler-service-vulnerability) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-04. https://nvd.nist.gov/vuln/detail/CVE-2021-34527

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-34527
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog