EXPOSURES › CVE-2021-34527
CVE-2021-34527
CRITICAL ⌖ ON CISA KEV · EXPLOITEDPrintNightmare allowed attackers to execute code with SYSTEM privileges on Windows systems via the Print Spooler service, actively exploited in ransomware attacks.
CVE-2021-34527, dubbed PrintNightmare, represents a critical vulnerability in the Windows Print Spooler service, enabling remote code execution with SYSTEM privileges. DIB organizations using Windows must immediately patch this vulnerability to prevent potential ransomware infections and data breaches, impacting NIST 800-171 controls related to access control and system integrity. Prioritize patching and review print server configurations.
Shame score — The widespread exploitation of a critical, remotely exploitable vulnerability in a core Windows service demonstrates a significant failure in Microsoft's secure development practices and resulted in significant real-world damage.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |