Skip to content
Critical Windows Print Spooler Vulnerability CVE-2021-34527 Exploited

Critical Windows Print Spooler Vulnerability CVE-2021-34527 Exploited

First seen 17 Jun 2026, 15:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 15:27 UTC
  • CVE-2021-34527 is a critical RCE vulnerability in Windows Print Spooler with a CVSS score of 8.8.
  • Successful exploitation requires authentication and affects all Windows versions by default.
  • Microsoft's updates are insufficient alone; disabling Point and Print is essential for full remediation.

CVE-2021-34527, known as 'PrintNightmare', is a critical remote code execution vulnerability affecting the Windows Print Spooler service. Initially thought to be related to CVE-2021-1675, it was identified on July 1, 2021, with a CVSSv3 score of 8.8. The vulnerability allows authenticated users to execute arbitrary code on vulnerable systems, affecting all versions of Windows. Microsoft released out-of-band updates on July 6 and 7, 2021, but additional steps are necessary for complete remediation, including disabling Point and Print. Exploitation in the wild has been detected, with tools like Mimikatz and Metasploit available for attackers. The situation remains critical, with potential for future ransomware campaigns leveraging this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2021-06-08
CVE-2021-1675 published
Microsoft disclosed a vulnerability in the Windows Print Spooler service with a CVSS score of 7.5.
Rapid7
2021-06-29
First public PoC for CVE-2021-1675
Public proof-of-concept exploits for CVE-2021-1675 began circulating, raising concerns about its security.
Rapid7
2021-07-01
CVE-2021-34527 identified
Microsoft clarified that the vulnerability exploited was CVE-2021-34527, not CVE-2021-1675.
Rapid7
2021-07-06
Microsoft releases out-of-band updates
Microsoft issued updates for CVE-2021-34527 to address the critical vulnerability in the Print Spooler service.
msrc-blog.microsoft.com
2021-07-08
Microsoft updates guidance on CVE-2021-34527
Revised guidance emphasized the importance of disabling Point and Print for effective remediation.
msrc-blog.microsoft.com
2021-11-03
CVE-2021-34527 added to CISA KEV
CVE-2021-34527 was added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Rapid7

More articles in this cluster (4)

Following this threat?

Track CVE-2021-1675 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed