Research / PrintNightmare (CVE-2021-1675 / CVE-2021-34527): RCE у Windows Print Spooler
RESEARCH
UA EN

PrintNightmare (CVE-2021-1675 / CVE-2021-34527): RCE in Windows Print Spooler

✍ di_yurich 📅 20.07.2026 👁 64

Overview

In June 2021, researchers accidentally leaked a PoC for a vulnerability in Windows Print Spooler (spoolsv.exe). It allowed an unprivileged local user to escalate to SYSTEM, and in some configurations — any authenticated network user to achieve RCE as SYSTEM.

Microsoft rushed a patch for CVE-2021-1675 (LPE), but the leaked PoC covered a different, unpatched vector — CVE-2021-34527 (RCE). This confusion left thousands of systems exposed weeks after the "official patch."


The Vulnerable Service

spoolsv.exe runs as SYSTEM on all Windows systems including Domain Controllers. The key function RpcAddPrinterDriverEx() — which adds printer drivers — failed to check permissions, allowing any authenticated user to load a DLL as SYSTEM.


CVE Split

  • CVE-2021-1675 — Local Privilege Escalation via local DLL path
  • CVE-2021-34527 — Remote Code Execution via UNC path (\attacker\share\evil.dll)

Domain Controllers running Print Spooler by default → any domain user → SYSTEM on DC → full domain compromise.


Detection

# Event ID 808 — new printer driver loaded
# Suspicious DLL in:
Get-ChildItem C:\Windows\System32\spool\driversd```

---

## Mitigation

```powershell
Stop-Service -Name Spooler -Force
Set-Service -Name Spooler -StartupType Disabled

Print Spooler on Domain Controllers is almost never needed — disable it.

Коментарі (0)
Увійди, щоб залишити коментар.
Коментарів поки немає.
Вперше тут?
Новачок на Bastion?
Почни з гайду користувача.
Відкрити гайд →
?