CVE detail
CVE-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
28 source links · newest first
The right tool can make or break a pentest or red team exercise. While many of the tools in Kali are tried and true, they are not always the best fit for every scenario. It is crucial to know where to turn for different needs, ensuring you’re adequately equipped to meet a variety of objectives. […]
newswww.csoonline.comOct 2, 2024, 10:00 AMCISA warns organizations of a two-year-old Windows Print Spooler vulnerability being exploited in the wild.
newswww.securityweek.comApr 24, 2024, 11:34 AMRussia-linked APT28 deploys the GooseEgg post-exploitation tool against numerous US and European organizations.
newswww.securityweek.comApr 23, 2024, 12:50 PMRussia-linked advanced persistent threat (APT) actor Forest Blizzard had, since June 2020, exploited a now-patched Windows vulnerability to drop previously unknown, custom post-compromise malware, GooseEgg, according to a Microsoft report. Forest Blizzard, linked previously to the Russian intelligence agency General Staff of the Armed Forces of the Russian Federation (GRU), deployed GooseEgg to gain elevated […]
newswww.csoonline.comApr 23, 2024, 11:28 AMVice Society, a ransomware gang, has been involved in high-profile activity against schools this year.
vendorunit42.paloaltonetworks.comDec 6, 2022, 11:00 AMRansom Cartel, a ransomware-as-a-service (RaaS) operation, has stepped up its attacks over the past year after the disbanding of prominent gangs such as REvil and Conti. Believed to have launched in December 2021, Ransom Cartel has made victims of organizations from among the education, manufacturing, utilities, and energy sectors with aggressive malware and tactics that […]
newswww.csoonline.comNov 30, 2022, 10:00 AMThe FBI, CISA, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are raising the alarm on a ransomware gang’s increased targeting of the education sector.
newswww.securityweek.comSep 7, 2022, 12:20 PMThe number of attacks targeting Windows Print Spooler vulnerabilities has been increasing, according to cybersecurity firm Kaspersky.
newswww.securityweek.comMay 11, 2022, 10:09 AM- Researchers Hack Conti Ransomware InfrastructureSecurityWeek
Prodaft security researchers exploited a vulnerability in the recovery servers used by the Conti Ransomware-as-a-Service (RaaS), which allowed them to gain insight into the inner workings of the ransomware.
newswww.securityweek.comNov 22, 2021, 3:55 PM On October 2021 Patch Tuesday, Microsoft has fixed 71 CVE-numbered vulnerabilities. Of those, only one was a zero-day exploited in attacks in the wild (CVE-2021-40449) and three were publicly known before the release of the patches. Vulnerabilities of note Let’s start with CVE-2021-40449, a Windows bug that may be used to escalate privileges on an already compromised system. Its exploitation was detected and flagged by Boris Larin, a zero-day exploits hunter with Kaspersky. According to … More →
newswww.helpnetsecurity.comOct 12, 2021, 7:35 PMAnother ransomware gang, the Vice Society ransomware operators, is using Windows print spooler PrintNightmare exploits in its attacks. The Vice Society ransomware operators are actively exploiting Windows print spooler PrintNightmare vulnerability in their attacks against Windows servers. The PrintNightmare flaws (tracked as (CVE-2021-1675, CVE-2021-34527, and CVE-2021-36958) reside in the Windows Print Spooler service, print drivers, and the Windows Point and […]
newssecurityaffairs.comAug 13, 2021, 5:16 PMThreat actors behind the Magniber Ransomware are using PrintNightmare exploits in attacks aimed at Windows servers. Threat actors behind the Magniber Ransomware are exploiting the PrintNightmare flaws (CVE-2021-1675, CVE-2021-34527, and CVE-2021-36958) to infect Windows servers. The PrintNightmare flaws reside in the Windows Print Spooler service, print drivers, and the Windows Point and Print feature. A few hours ago […]
newssecurityaffairs.comAug 12, 2021, 4:01 PM- There are new unpatched bugs in Windows Print SpoolerHelp Net Security
Security researchers have unearthed new elevation of privilege (EoP) bugs in Windows Print Spooler, one of the oldest Windows components. Scarce details have been shared about the first one (CVE-2021-34481), aside from the note that it “exists when the Windows Print Spooler service improperly performs privileged file operations,” and can be exploited by an attacker to elevate privilege to SYSTEM level (then run arbitrary code with those privileges). The other (currently without a CVE) is … More →
newswww.helpnetsecurity.comJul 19, 2021, 9:59 AM - Microsoft alerts about a new Windows Print Spooler vulnerabilitySecurity Affairs
Microsoft published guidance to mitigate the impact of a new Windows Print Spooler vulnerability tracked as CVE-2021-34481 that was disclosed today. Microsoft published a security advisory for a new Windows Print Spooler vulnerability, tracked as CVE-2021-34481, that was disclosed on Thursday. The flaw is a privilege elevation vulnerability that resides in the Windows Print Spooler, it was […]
newssecurityaffairs.comJul 16, 2021, 2:15 PM We share details of and mitigation actions for a Windows Print Spooler RCE vulnerability, CVE-2021-34527, also known as PrintNightmare.
vendorunit42.paloaltonetworks.comJul 14, 2021, 11:00 PM- Did Microsoft Botch the PrintNightmare Patch?SecurityWeek
Just days after shipping an emergency Windows update to cover a dangerous code execution flaw ( CVE-2021-1675 ) in the Print Spooler service, Microsoft is investigating a new set of claims that its so-called ‘PrintNightmare’ patch has not properly fixed the underlying vulnerability.
newswww.securityweek.comJul 9, 2021, 1:55 PM - July 2021 Patch Tuesday forecast: Don’t wait for Patch TuesdayHelp Net Security
There’s been lots of excitement around the recently announced print spooler vulnerability CVE-2021-34527, commonly referred to as PrintNightmare. The excitement stems from the fact that this vulnerability has a CVSS score of 8.8, is present in ALL Windows operating systems, has been publicly disclosed with known exploits, and allows an attacker to easily execute remote code with system privileges. This vulnerability comes from functionality that allows users to install printer drivers on their systems. The … More →
newswww.helpnetsecurity.comJul 9, 2021, 6:00 AM Microsoft has started releasing emergency security updates to fix a publicly disclosed remote code execution vulnerability in the Windows printing functionality that could allow attackers to take full control of vulnerable systems. The vulnerability, dubbed PrintNightmare and tracked as CVE-2021-34527, is located in the Windows Print Spooler service and the public exploits available for it […]
newswww.csoonline.comJul 7, 2021, 12:50 PMMicrosoft rolled out KB5004945 emergency update to address the actively exploited PrintNightmare zero-day vulnerability (CVE-2021-34527) in Print Spooler service. Microsoft has released the KB5004945 emergency security update to address the actively exploited CVE-2021-34527 zero-day vulnerability, aka PrintNightmare. “A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An […]
newssecurityaffairs.comJul 7, 2021, 7:47 AMMicrosoft late Tuesday pushed out an emergency patch to cover the Windows ‘PrintNightmare’ security flaw.
newswww.securityweek.comJul 6, 2021, 9:40 PM- Security Affairs newsletter Round 321Security Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the international press subscribe here. Crackonosh Monero miner made $2M after infecting 222,000 Win systems Hackers target Cisco ASA devices after a PoC […]
newssecurityaffairs.comJul 4, 2021, 11:55 AM - Week in review: PoC for Windows Print Spooler flaw leaked, conquering synthetic identity fraudHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: PoC for critical Windows Print Spooler flaw leaked Microsoft has confirmed that the so-called PrintNightmare vulnerability (CVE-2021-34527) is not the same flaw as the previously patched CVE-2021-1675, and that the leaked PoC exploits can be used to exploit this RCE zero-day. Cisco security devices targeted with CVE-2020-3580 PoC exploit Attackers and bug hunters are leveraging an exploit for CVE-2020-3580 to compromise vulnerable … More →
newswww.helpnetsecurity.comJul 4, 2021, 8:00 AM Microsoft late Thursday acknowledged a severe security vulnerability in the Print Spooler utility that ships by default on Windows and warned that the bug exposes users to computer takeover attacks.
newswww.securityweek.comJul 2, 2021, 2:20 PMCISA issued a security alert to warn admins to disable the Windows Print Spooler service on servers not used for printing due to PrintNightmare zero-day. CISA issued an alert to warn admins to disable the Windows Print Spooler on servers not used for printing due to the risk of exploitation of the PrintNightmare zero-day vulnerability. ““while Microsoft […]
newssecurityaffairs.comJul 2, 2021, 8:53 AMIn a rush to be the first to publish a proof-of-concept (PoC), researchers have published a write-up and a demo exploit…
newswww.malwarebytes.comJun 30, 2021, 5:00 PMWindows network administrators are scrambling to contain the fallout from the release of proof-of-concept code for a nasty Windows Print Spooler vulnerability that exposes Windows servers to remote code execution attacks.
newswww.securityweek.comJun 30, 2021, 2:08 PM- PoC for critical Windows Print Spooler flaw leaked (CVE-2021-1675)Help Net Security
CVE-2021-1675, a Windows Print Spooler vulnerability that Microsoft patched in June 2021, presents a much greater danger than initially thought: researchers have proved that it can be exploited to achieve remote code execution and – what’s worse – PoC exploits have since been leaked. About CVE-2021-1675 Credited to Zhipeng Huo of Tencent Security Xuanwu Lab, Piotr Madej of AFINE and Yunhai Zhang of NSFOCUS TIANJI Lab, CVE-2021-1675 was initially classed as low severity vulnerability, allowing … More →
newswww.helpnetsecurity.comJun 30, 2021, 12:46 PM - PoC exploit for CVE-2021-1675 RCE started circulating onlineSecurity Affairs
Proof-of-concept exploit code for CVE-2021-1675 flaw, an attacker could exploit it to compromise Windows systems. Proof-of-concept exploit code for the CVE-2021-1675 flaw has been published online, the flaw impacts the Windows Print Spooler service and could be exploited to compromise Windows systems. Microsoft addressed the flaw with the release of Microsoft June 2021 Patch Tuesday […]
newssecurityaffairs.comJun 29, 2021, 5:07 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-43226CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed3 mentions - CVE-2021-41379CVSS 5.5 · Medium
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-40449CVSS 7.8 · High
Win32k Elevation of Privilege Vulnerability
- CVE-2021-40444CVSS 8.8 · High
<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exp…
- CVE-2021-36955CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed1 mention - CVE-2021-34484CVSS 7.8 · High
Windows User Profile Service Elevation of Privilege Vulnerability
KEV listed4 mentions