PrintNightmare (CVE-2021-34527) is a critical vulnerability in the Windows Print Spooler service enabling both remote code execution and local privilege escalation. The June 8 Microsoft patch did not fully resolve the issue. Temporary mitigations include disabling the Print Spooler service via PowerShell or Group Policy, or restricting ACLs on the spool drivers directory to prevent malicious DLL drops. Detection can be achieved by enabling Microsoft-Windows-PrintService/Operational logging and monitoring for Event ID 316 or ImageLoad events tied to spoolsv.exe. Public PoCs exist in Python and C++ and have been confirmed to work against Windows Server 2016 and 2019. An emergency patch was released July 6 but remains under scrutiny, as privilege escalation still succeeds on some Windows Server versions.

9m read timeFrom huntress.com
Post cover image
Table of contents
What Does PrintNightmare Do?What Should MSPs Do?What Is Huntress Doing?Learn More: Research and Intelligence