Critical Windows Print Spooler Vulnerability CVE-2021-34527 Exploited

Critical Windows Print Spooler Vulnerability CVE-2021-34527 Exploited

First seen 17 Jun 2026, 15:59 UTC Rapid7msrc-blog.microsoft.comsupport.microsoft.commsrc.microsoft.com 89% similarity 72.8

Article Content

Browse articles
ThreatCluster

CVE-2021-34527, known as 'PrintNightmare', is a critical remote code execution vulnerability affecting the Windows Print Spooler service. Initially thought to be related to CVE-2021-1675, it was identified on July 1, 2021, with a CVSSv3 score of 8.8. The vulnerability allows authenticated users to execute arbitrary code on vulnerable systems, affecting all versions of Windows. Microsoft released out-of-band updates on July 6 and 7, 2021, but additional steps are necessary for complete remediation, including disabling Point and Print. Exploitation in the wild has been detected, with tools like Mimikatz and Metasploit available for attackers. The situation remains critical, with potential for future ransomware campaigns leveraging this vulnerability.

Key Points: • CVE-2021-34527 is a critical RCE vulnerability in Windows Print Spooler with a CVSS score of 8.8. • Successful exploitation requires authentication and affects all Windows versions by default. • Microsoft's updates are insufficient alone; disabling Point and Print is essential for full remediation.

ThreatCluster AI How this analysis works

Timeline

2021-06-08
CVE-2021-1675 published
Microsoft disclosed a vulnerability in the Windows Print Spooler service with a CVSS score of 7.5.
Rapid7
2021-06-29
First public PoC for CVE-2021-1675
Public proof-of-concept exploits for CVE-2021-1675 began circulating, raising concerns about its security.
Rapid7
2021-07-01
CVE-2021-34527 identified
Microsoft clarified that the vulnerability exploited was CVE-2021-34527, not CVE-2021-1675.
Rapid7
2021-07-06
Microsoft releases out-of-band updates
Microsoft issued updates for CVE-2021-34527 to address the critical vulnerability in the Print Spooler service.
msrc-blog.microsoft.com
2021-07-08
Microsoft updates guidance on CVE-2021-34527
Revised guidance emphasized the importance of disabling Point and Print for effective remediation.
msrc-blog.microsoft.com
2021-11-03
CVE-2021-34527 added to CISA KEV
CVE-2021-34527 was added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Rapid7

Community

Browse all →

Tracked Entities in This Story