Skip to content
COOEY

EXPOSURES › CVE-2021-34527

CVE-2021-34527

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-34527 ↗
⚡ RCE ◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

PrintNightmare allowed attackers to execute code with SYSTEM privileges on Windows systems via the Print Spooler service, actively exploited in ransomware attacks.

CVE-2021-34527, dubbed PrintNightmare, represents a critical vulnerability in the Windows Print Spooler service, enabling remote code execution with SYSTEM privileges. DIB organizations using Windows must immediately patch this vulnerability to prevent potential ransomware infections and data breaches, impacting NIST 800-171 controls related to access control and system integrity. Prioritize patching and review print server configurations.

Shame score — The widespread exploitation of a critical, remotely exploitable vulnerability in a core Windows service demonstrates a significant failure in Microsoft's secure development practices and resulted in significant real-world damage.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
handled well
cooey ↗ severe-fallout -0.70
handled well
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized