---
title: "Windows PrintNightmare Vulnerability"
canonical: "https://www.virtcloudrocks.com/space/INFOSEC/blog/852347/Windows%20PrintNightmare%20Vulnerability"
format: markdown
---
<span style="color: #000000">On June 29, 2021, public exploits began circulating for a critical remote code execution vulnerability in the Windows Print Spooler service. While it was initially believed that these exploits targeted an incomplete patch for CVE-2021-1675, which was patched earlier in June, Microsoft clarified on July 1, 2021 that what the community had discovered was CVE-2021-34527, a new vulnerability in the Windows Print Spooler, also known as “PrintNightmare.” Microsoft published a </span>[new advisory](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Finfo.rapid7.com%2FNDExLU5BSy05NzAAAAF-JlByxkT8s7fPSG28MQ3yD3xCJ5OSChCOnEvGAkfakgBLndn3KsV4yRBViOY8j0AkvCOdF2I%3D&data=04%7C01%7C%7Cc9de04a6849b4d15474c08d9423ccc54%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C1%7C637613651158241654%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=2PLti2GHISn2fp91wRGpIYQoP%2BYCr1CfMmB2MxU1HCA%3D&reserved=0)<span style="color: #000000"> and issued out-of-band patches for CVE-2021-34527 on July 6 and July 7, 2021. CVE-2021-34527 affects all versions of Windows.</span>

<span style="color: #000000">CVE-2021-34527 is being actively exploited in the wild, and public exploit code is readily available. For more information and a full timeline, see </span>[Rapid7’s blog on PrintNightmare](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Finfo.rapid7.com%2FNDExLU5BSy05NzAAAAF-JlByxtg72KZN20kpFcgtLHOMNCsXVTn4rnE3D8ETqKwesFWFnAvAO--Oqd9d0MM3Fghg890%3D&data=04%7C01%7C%7Cc9de04a6849b4d15474c08d9423ccc54%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C1%7C637613651158241654%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=NmLAfMthOwVXrG7M8hiT1DSACyQWvj9jkUXF5rRqY50%3D&reserved=0)<span style="color: #000000">.</span>

**Next Steps**  
<span style="color: #000000">Rapid7 recommends that all customers </span>**<span style="color: #000000">install the July 6, 2021 out-of-band updates </span>**<u>**<span style="color: #000000">AND</span>**</u>**<span style="color: #000000"> disable Point and Print</span>**<span style="color: #000000">. This second step is critical—Rapid7 and community researchers have confirmed that remote code execution is still possible as long </span>**<span style="color: #000000">as </span>**[**<span style="color: #000000">Point and Print </span>**](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Finfo.rapid7.com%2FNDExLU5BSy05NzAAAAF-JlByxpPGUhYuzb63XzNT661fFOq1ptoqRLY13lil1GBok4vlyzNKU4P4GCg9bpdsDbeSC_s%3D&data=04%7C01%7C%7Cc9de04a6849b4d15474c08d9423ccc54%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C1%7C637613651158251651%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=w2ctd9hEwe5ZW8BsRnI5nG7tFybDLgGWVkFiRttarZQ%3D&reserved=0)**<span style="color: #000000">is enabled</span>**<span style="color: #000000">. Alternatively, if you do not require printing to conduct business operations, you may disable the Windows Print Spooler service altogether on an emergency basis to mitigate the immediate risk of exploitation.</span>

<span style="color: #000000">To learn more about the PrintNightmare vulnerability and next steps for emergency remediation, read our </span>[blog post](https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Finfo.rapid7.com%2FNDExLU5BSy05NzAAAAF-JlByxtg72KZN20kpFcgtLHOMNCsXVTn4rnE3D8ETqKwesFWFnAvAO--Oqd9d0MM3Fghg890%3D&data=04%7C01%7C%7Cc9de04a6849b4d15474c08d9423ccc54%7C0edca4720b7146e696c70a68c10dcb96%7C0%7C1%7C637613651158251651%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=RMwLU5LPdnmv%2FQuN6oBeVy8Vhg6mQ%2Fwm7PSTragV2ig%3D&reserved=0)<span style="color: #000000">.</span>