CVE-2021-1675General(microsoft / windows_10_1507)

LOWCVSS 7.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Windows Print Spooler Remote Code Execution Vulnerability

2.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_1909

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_1909windows_10_2004windows_10_20h2windows_10_21h1windows_7windows_8.1windows_rt_8.1

2 versions affected across 15 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-03: 1Mentions · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-08: 1Technical Details · 2026-07-08: 103-0307-08
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-031
General1
2026-07-081
Disclosure1
Full discourse2 posts
  • OS Dev@OSdev_
    Disclosure

    PrintNightmare is a great example of how a service that's enabled by default can become a critical attack surface. The vulnerability affected the Windows Print Spooler service and was tracked as CVE-2021-1675 and CVE-2021-34527. The confusion around these two CVEs, combined with the accidental release of a proof-of-concept before a complete patch was available, turned it into one of the most high-profile Windows vulnerabilities in recent years. The attack abused the RpcAddPrinterDriverEx functionality to load a malicious printer driver DLL. With valid credentials and the Print Spooler service enabled, an attacker could execute arbitrary code with SYSTEM privileges. Since the Print Spooler runs by default on many Windows systems including Domain Controllers the potential impact was enormous. What makes PrintNightmare worth studying isn't just the exploit. It highlights how RPC, driver loading, SMB shares, printer driver installation, and Windows privilege boundaries interact inside the operating system. It's an excellent case study in how legacy functionality, complex service design, and incomplete patches can combine into a major security incident.

    Post summary

    PrintNightmare revealed a critical flaw in Windows Print Spooler that permits remote code execution through malicious printer drivers, with an accidental proof‑of‑concept release underscoring the urgency before patches were available.

    210040133.3K
    5.0K followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed PrintNightmare room on TryHackMe! Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527). https://tryhackme.com/room/printnightmarehpzqlp8?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The post references a TryHackMe room covering PrintNightmare (CVE-2021-1675 and CVE-2021-34527) but provides no technical details, PoC, or exploitation information.

    0000033
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_1909---
OSmicrosoftwindows_10_2004---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h1---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2004---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---

Explore more