Vulnerability Intelligence

🛡 CVE-2021-34527

Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows CWE-269

Ransomware use

KNOWN
CISA KEV

EPSS

99.8%
Likely exploited · 100th pct

Added to KEV

2021-11-03
CISA

Remediate by

2022-05-03
⚠ OVERDUE

CWE

CWE-269
weakness

📈 EPSS exploit probability

99.8%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 100% of all scored CVEs

⚠ KEV remediation overdue

CISA required federal remediation by 2022-05-03. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.

📄 Description

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution wit

🏹 Attributed exploitation

Malware / ransomware (KEV): Vice Society, Magniber, Conti (PrintNightmare)

Threat actors (KEV): Vice Society

Actor pivots: 🏹 Vice Society
Malware pivots: 🦠 Vice Society 🦠 Magniber 🦠 Conti 🦠 Conti (PrintNightmare)

🛡 Add to case

Attach CVE-2021-34527 (Vulnerability / CVE) and pull all linked entities:
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php