CVE-2021-34527: PrintNightmare
A vulnerability in the Windows Print Spooler service caused by improper handling of privileged file operations. An authenticated attacker, including a low-privileged domain user, can install a malicious printer driver that runs as SYSTEM, achieving remote code execution or local privilege escalation.
View the authoritative record on NVD ↗Affected software
- Windows Print Spooler service on most supported Windows client and Server versions (2021)
How it's exploited
Call the Print Spooler's RpcAddPrinterDriverEx RPC method with a path to an attacker-supplied driver DLL; the spooler loads and runs it with SYSTEM privileges.
Severity
CVE-2021-34527 carries a CVSS 3.1 base score of 8.8, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2021-34527 is categorized under CWE-269, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
For AI/LLM targets, TurboPentest's agentic pentest tests for excessive agency by adversarially prompting the model, via Paladin AI, to invoke tools or take actions beyond its intended privileges, following the OWASP LLM Top 10 (LLM06) and MITRE ATLAS. A manual IntegSec engagement adds even deeper methodology and a larger context window on top of that automated coverage.
Tools: Paladin AI
Remediation
Apply Microsoft's June/July 2021 out-of-band security updates, and where printing is not needed, disable the Print Spooler service or restrict inbound printing through Group Policy.
Frequently asked questions
What is CVE-2021-34527?
A vulnerability in the Windows Print Spooler service caused by improper handling of privileged file operations. An authenticated attacker, including a low-privileged domain user, can install a malicious printer driver that runs as SYSTEM, achieving remote code execution or local privilege escalation.
How severe is CVE-2021-34527?
CVE-2021-34527 has a CVSS 3.1 base score of 8.8 out of 10, rated High.
What software is affected by CVE-2021-34527?
CVE-2021-34527 affects Windows Print Spooler service on most supported Windows client and Server versions (2021).
How do you fix CVE-2021-34527?
Apply Microsoft's June/July 2021 out-of-band security updates, and where printing is not needed, disable the Print Spooler service or restrict inbound printing through Group Policy.
Where is the authoritative record for CVE-2021-34527?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2021-34527 at https://nvd.nist.gov/vuln/detail/CVE-2021-34527, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest