🛡 CVE-2021-34527
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows CWE-269
Ransomware use
KNOWN
CISA KEV
EPSS
99.8%
Likely exploited · 100th pct
Added to KEV
2021-11-03
CISA
Remediate by
2022-05-03
⚠ OVERDUE
CWE
CWE-269
weakness
📈 EPSS exploit probability
99.8%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 100% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2022-05-03. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution wit
🏹 Attributed exploitation
Malware / ransomware (KEV): Vice Society, Magniber, Conti (PrintNightmare)
Threat actors (KEV): Vice Society
Actor pivots: 🏹 Vice Society
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron