Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

Published 3 Aug 2026Updated 3 Aug 202630 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

What happened

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

Affected versions

Windows: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · DenizSe/CVE-2021-34527Small Powershell Script to detect Running Printer Spoolers on Domain Controller★ 0DenizSe2021-07-01CandidatePoC-in-GitHub · JohnHammond/CVE-2021-34527★ 325JohnHammond2021-07-02CandidatePoC-in-GitHub · twi1ight00/PrintNightmareKritische Sicherheitslücke PrintNightmare CVE-2021-34527★ 0twi1ight002021-07-03CandidatePoC-in-GitHub · nemo-wq/PrintNightmare-CVE-2021-34527PrintNightmare - Windows Print Spooler RCE/LPE Vulnerability (CVE-2021-34527, CVE-2021-1675) proof of concept exploits★ 176nemo-wq2021-07-03CandidatePoC-in-GitHub · rdboboia/disable-RegisterSpoolerRemoteRpcEndPointWorkaround for Windows Print Spooler Remote Code Execution Vulnerability(CVE-2021-34527). See: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527★ 2rdboboia2021-07-05CandidatePoC-in-GitHub · geekbrett/CVE-2021-34527-PrintNightmare-WorkaroundThis simple PowerShell script is in response to the "PrintNightmare" vulnerability. This was designed to give a end user the ability to stop and disable the "Print Spooler" service on their computer while awaiting a fix from Microsoft.★ 0geekbrett2021-07-05CandidatePoC-in-GitHub · byt3bl33d3r/ItWasAllADreamA PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE★ 800byt3bl33d3r2021-07-05CandidatePoC-in-GitHub · vinaysudheer/Disable-Spooler-Service-PrintNightmare-CVE-2021-34527Simple batch script to disable the Microsoft Print Spooler service from system★ 0vinaysudheer2021-07-07CandidatePoC-in-GitHub · powershellpr0mpt/PrintNightmare-CVE-2021-34527How to fix the PrintNightmare vulnerability★ 2powershellpr0mpt2021-07-07CandidatePoC-in-GitHub · WidespreadPandemic/CVE-2021-34527_ACL_mitigationMitigation for CVE-2021-34527 RCE by setting WRITE ACLs★ 0WidespreadPandemic2021-07-08CandidatePoC-in-GitHub · glorisonlai/printnightmareCVE-2021-34527 implementation★ 0glorisonlai2021-07-08CandidatePoC-in-GitHub · dywhoami/CVE-2021-34527-Scanner-Based-On-cube0x0-POC★ 3dywhoami2021-07-09CandidatePoC-in-GitHub · Eutectico/PrintnightmareFix for PrintNightmare CVE-2021-34527★ 0Eutectico2021-07-09CandidatePoC-in-GitHub · syntaxbearror/PowerShell-PrintNightmareA collection of scripts to help set the appropriate registry keys for CVE-2021-34527★ 0syntaxbearror2021-07-09CandidatePoC-in-GitHub · 0xirison/PrintNightmare-PatcherA patch for PrintNightmare vulnerability that occurs to print spooler service for Windows machines [CVE-2021-34527]★ 20xirison2021-07-12CandidatePoC-in-GitHub · fengjixuchui/CVE-2021-34527-1675Cve-2021-1675 or cve-2021-34527? Detailed analysis and exploitation of windows print spooler 0day vulnerability!!!★ 0fengjixuchui2021-07-13CandidatePoC-in-GitHub · Tomparte/PrintNightmareTo fight against Windows security breach PrintNightmare! (CVE-2021-34527, CVE-2021-1675)★ 3Tomparte2021-07-28CandidatePoC-in-GitHub · Amaranese/CVE-2021-34527★ 1Amaranese2021-12-13CandidatePoC-in-GitHub · cyb3rpeace/CVE-2021-34527★ 1cyb3rpeace2022-06-24CandidatePoC-in-GitHub · m8sec/CVE-2021-34527PrintNightmare (CVE-2021-34527) PoC Exploit★ 118m8sec2022-08-23CandidatePoC-in-GitHub · hackerhouse-opensource/cve-2021-34527CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation★ 23hackerhouse-opensource2022-09-05CandidatePoC-in-GitHub · d0rb/CVE-2021-34527CVE-2021-34527 PrintNightmare PoC★ 0d0rb2023-08-20CandidatePoC-in-GitHub · TieuLong21Prosper/detect_bruteforcedetect bruteforce using for cve-2021-34527★ 0TieuLong21Prosper2023-10-28CandidatePoC-in-GitHub · Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784★ 0Hirusha-N2024-06-25CandidatePoC-in-GitHub · AUSK1LL9/CVE-2021-34527CVE-2021-34527 is a critical remote code execution and local privilege escalation vulnerability dubbed "PrintNightmare."★ 0AUSK1LL92025-05-21CandidatePoC-in-GitHub · AlDawli/CVE-2021-34527-PrintNightmare Report★ 0AlDawli2026-05-27CandidatePoC-in-GitHub · KaritaMW/printnightmare-detection-mitigation-labSanitised Windows security lab demonstrating Active Directory administration, host and network detection, and layered mitigation of CVE-2021-34527.★ 0KaritaMW2026-08-03CandidatePoC-in-GitHub · joertx07/printnightmare-detection-labSplunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection rules.★ 0joertx072026-08-04Candidate