CVE-2021-34527Patch(microsoft / windows_10_1507)

HIGHCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. In addition to installing the updates, in order to secure your system, you must confirm that the following registry settings are set to 0 (zero) or are not defined (Note: These registry keys do not exist by default, and therefore are already at the secure setting.), also that your Group Policy setting are correct (see FAQ): HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint NoWarningNoElevationOnInstall = 0 (DWORD) or not defined (default setting) UpdatePromptSettings = 0 (DWORD) or not defined (default setting) Having NoWarningNoElevationOnInstall set to 1 makes your system vulnerable by design. UPDATE July 6, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. See also KB5005010: Restricting installation of new printer drivers after applying the July 6, 2021 updates. Note that the security updates released on and after July 6, 2021 contain protections for CVE-2021-1675 and the additional remote code execution exploit in the Windows Print Spooler service known as “PrintNightmare”, documented in CVE-2021-34527.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Vendor / third-party advisories

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_20h2

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 13 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • General: 4 classified signals
  • Peaked 5d ago at 2 mentions (2026-04-21); latest day: 1
  • 14 total mentions across 13 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_20h2windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_rt_8.1windows_server_2008

2 versions affected across 15 products

Deep dive

Activity timeline14 mentions / 13d
01122Mentions · 2026-02-06: 1Mentions · 2026-02-27: 1Mentions · 2026-03-03: 1Mentions · 2026-03-11: 1Mentions · 2026-03-18: 1Mentions · 2026-04-06: 1Mentions · 2026-04-08: 1Mentions · 2026-04-21: 2Mentions · 2026-04-23: 1Mentions · 2026-04-30: 1Mentions · 2026-05-15: 1Mentions · 2026-07-08: 1Mentions · 2026-09-27: 1PoC Mentioned / Linked · 2026-07-08: 1Active Exploitation · 2026-02-06: 1Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-09-27: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-21: 2Technical Details · 2026-04-06: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-23: 1Technical Details · 2026-07-08: 102-0602-2703-0303-1103-1804-0604-0804-2104-2304-3005-1507-0809-27
Signal classification4 categories
Patch
535.7%
General
428.6%
Active Exploitation
321.4%
Disclosure
214.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-061
Active Exploitation1
2026-02-271
Patch1
2026-03-031
General1
2026-03-111
Active Exploitation1
2026-03-181
Patch1
2026-04-061
Patch1
2026-04-081
Disclosure1
2026-04-212
Patch2
2026-04-231
General1
2026-04-301
General1
2026-05-151
General1
2026-07-081
Disclosure1
2026-09-271
Active Exploitation1
Full discourse14 posts
  • OS Dev@OSdev_
    Disclosure

    PrintNightmare is a great example of how a service that's enabled by default can become a critical attack surface. The vulnerability affected the Windows Print Spooler service and was tracked as CVE-2021-1675 and CVE-2021-34527. The confusion around these two CVEs, combined with the accidental release of a proof-of-concept before a complete patch was available, turned it into one of the most high-profile Windows vulnerabilities in recent years. The attack abused the RpcAddPrinterDriverEx functionality to load a malicious printer driver DLL. With valid credentials and the Print Spooler service enabled, an attacker could execute arbitrary code with SYSTEM privileges. Since the Print Spooler runs by default on many Windows systems including Domain Controllers the potential impact was enormous. What makes PrintNightmare worth studying isn't just the exploit. It highlights how RPC, driver loading, SMB shares, printer driver installation, and Windows privilege boundaries interact inside the operating system. It's an excellent case study in how legacy functionality, complex service design, and incomplete patches can combine into a major security incident.

    Post summary

    The post outlines the PrintNightmare Windows Print Spooler vulnerability (CVE-2021-1675/34527), detailing its exploitation via malicious printer drivers and emphasizing its high-profile nature.

    210040133.3K
    5.0K followersView on X
  • Jordano Mazzoni | Cybersecurity@jordano_mazzoni
    Patch

    Windows - Hardening Básico - Part 33 - Print Spooler to accept client connections O serviço de Spooler de Impressão (historicamente onipresente) tornou-se um vetor de alto risco com a descoberta da vulnerabilidade PrintNightmare (CVE-2021-34527), que permite a execução remota de código com privilégios de sistema. Como medida de mitigação prioritária, especialmente em Controladores de Domínio e servidores que não desempenham o papel de servidores de impressão, a desativação da capacidade do serviço de aceitar conexões de entrada é fundamental. Esta configuração isola o serviço de requisições externas, neutralizando vetores de ataque remotos conhecidos, embora a vigilância contra vetores locais deva permanecer no radar da equipe de SOC. Considere também desabilitar no escopo Desktops e Estações de Trabalho. Garanta que 'Allow Print Spooler to accept client connections' esteja atribuido como 'Disabled' https://x.com/jordano_mazzoni/status/2041127111662899275

    Post summary

    The tweet instructs disabling the Print Spooler’s client connection feature to mitigate the PrintNightmare CVE‑2021‑34527 remote code execution vulnerability.

    000802.3K
    3.2K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    @TobieGraphix Insurance in AI is a double-edged sword; while it mitigates risks from incidents like the 2021 AWS outage (CVE-2021-34527), it can also entrench complacency in security measures. Are we insuring innovation or inviting negligence?

    Post summary

    The statement references a past vulnerability (CVE-2021-34527) in the context of an AWS outage but offers no additional details on the flaw, its exploitation, or mitigation.

    1001051
    128 followersView on X
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    Print Spooler became a high-risk vector after PrintNightmare (CVE-2021-34527) enabled remote code execution with system privileges. Disable the ability to accept client connections on Domain Controllers and non-print servers to isolate the service from external requests. Set 'Allow Print Spooler to accept client connections' to Disabled under Computer Configuration\Policies\Administrative Templates\Printers. Restart the Print Spooler service for the policy to take effect; this mitigates remote attacks but not local ones. Users can still print locally; shared printers remain shared, but new client connections and printer sharing are blocked.

    Post summary

    The text focuses on a mitigation strategy—disabling external client connections—to protect against the CVE‑2021‑34527 remote code execution vulnerability.

    0002042
    3.2K followersView on X
  • David@davidsheyi
    Patch

    3/ These actors leverage CVE-2021-34527 (PrintNightmare) to gain initial access. Stay updated on patches to mitigate this threat. #InfoSec #Security

    Post summary

    The post notes that attackers use PrintNightmare (CVE‑2021‑34527) for initial access and urges keeping patches updated to mitigate the threat.

    1001021
    555 followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text lists numerous Windows CVE identifiers without providing any additional context, details, or actionable information.

    10000106
    15 followersView on X
  • David@davidsheyi
    Active Exploitation

    2/ A notable incident: LockBit attacked Accenture in 2021, demanding $50M. Their use of CVE-2021-34527 exploits highlights the need for timely patching #ThreatIntel #InfoSec

    Post summary

    The post documents a LockBit attack on Accenture that exploited CVE‑2021‑34527, emphasizing the need for timely patching.

    1000073
    557 followersView on X
  • David@davidsheyi
    Patch

    6/ CVE-2021-34527 (PrintNightmare) is an example of network vulnerabilities exploited for lateral movement. Patch systems promptly and monitor print spooler services #NetworkSecurity #CyberSecurity

    Post summary

    CVE-2021-34527 (PrintNightmare) is cited as an example of lateral movement exploitation, and the advisory urges prompt patching and monitoring of print spooler services.

    1000025
    556 followersView on X
  • David@davidsheyi
    Active Exploitation

    4/ Consider CVE-2021-34527 'PrintNightmare'. EDRs detect exploitation attempts, alerting teams before damage occurs. #SOC #DFIR

    Post summary

    The post notes that CVE-2021-34527 (PrintNightmare) is being actively targeted, with EDRs detecting exploitation attempts, but it provides no PoC, exploit code, patch, or technical details.

    1000055
    556 followersView on X
  • Ashvin Aacharya@0xAshvin
    Active Exploitation

    🕵️ Investigated PrintNightmare (CVE-2021-34527) on @LetsDefendIO correlating PCAP and endpoint evidence to reconstruct the attack chain — from SMB and malicious DLL delivery to persistence and Meterpreter post-exploitation. #CyberSecurity #SOC #DFIR 🔗 https://github.com/0xAshvin/Soc-investigation https://t.co/j6D5uo2p4b

    Post summary

    The post details an investigation of a PrintNightmare attack, highlighting real-world exploitation through SMB, DLL delivery, and post-exploitation activities.

    0000032
    3 followersView on X
  • SecLab Brasil@SecLabBrasil
    General

    PrintNightmare (CVE-2021-34527): Ate hoje existem servers nao patcheados 1 exploit = SYSTEM imediato via Print Spooler Verifique: Get-Service -Name Spooler Se rodando = pode ser vulneravel

    Post summary

    The note alerts that unpatched servers may be vulnerable to CVE‑2021‑34527 (PrintNightmare), where a single exploit can grant SYSTEM via the Print Spooler, but no PoC, tool, or active exploitation details are supplied.

    0000023
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    PrintNightmare (CVE-2021-34527) によってシステム権限でのリモートコード実行が可能になったため、Print Spooler は高リスクな攻撃経路となりました。 外部からのリクエストからサービスを隔離するために、ドメイン コントローラーおよび非印刷サーバーでクライアント接続の受け入れを無効にしてください。 [コンピューターの構成] > [ポリシー] > [管理用テンプレート] > [プリンター] で、[Print Spooler がクライアント接続を受け入れることを許可する] を [無効] に設定してください。 ポリシーを有効にするには、Print Spooler サービスを再起動してください。これによりリモート攻撃は軽減されますが、ローカル攻撃は軽減されません。 ユーザーは引き続きローカルで印刷できます。共有プリンターは共有されたままですが、新しいクライアント接続とプリンターの共有はブロックされます。

    Post summary

    The text describes the PrintNightmare CVE‑2021‑34527 remote code execution risk and recommends disabling external client connections and restarting the Print Spooler service to mitigate the threat.

    0000034
    3.2K followersView on X
  • Jordano Mazzoni | Cybersecurity@jordano_mazzoni
    Disclosure

    Windows - Hardening Básico - Part 33 - Print Spooler to accept client connections O serviço de Spooler de Impressão (historicamente onipresente) tornou-se um vetor de alto risco com a descoberta da vulnerabilidade PrintNightmare (CVE-2021-34527), que permite a execução remota de código com privilégios de sistema. https://x.com/jordano_mazzoni/status/2041777153386192938?s=20

    Post summary

    The post highlights the discovery of CVE-2021-34527 (PrintNightmare) in the Windows Print Spooler, noting its risk of remote code execution with system privileges, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000049
    2.3K followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed PrintNightmare room on TryHackMe! Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527). https://tryhackme.com/room/printnightmarehpzqlp8?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The post references the PrintNightmare vulnerability (CVE-2021-1675 and CVE-2021-34527) and directs readers to a TryHackMe room for learning, but provides no technical details, PoC, or exploitation information.

    0000033
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_20h2---

Explore more