Code Injection in Microsoft Windows and Windows Server - CVE-2021-1675
Published: July 2, 2021 / Updated: September 4, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation within the Windows Print Spooler service. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note, this is a description of the original vulnerability fixed by Microsoft on June 9, 2021. A different vulnerability than #VU53886 (CVE-2021-34527) for which an exploit was made publicly available.
Affected software
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2021-1675
Solutions Enabler - addressed in versions 9.1.0.17, 9.2.2.0
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.28, 9.2.2.2
Unisphere for PowerMax - addressed in versions 9.1.0.28, 9.2.2.2
Links to Public Exploits and PoC-codes
- Exploit #8337 - Exploits (All CVE Exploits used by connor including code.) (September 4, 2022)
- Exploit #7887 - Print Spooler Remote DLL Injection (May 24, 2022)
- Exploit #7335 - NimNightmare (CVE-2021-1675 LPE PoC in Nim (PrintNightmare Local Privilege Escalation)) (February 9, 2022)
- Exploit #7322 - CVE-2021-1675 (PrintNightmare Local Privilege Escalation ) (February 6, 2022)
- Exploit #7103 - NimNightmare (CVE-2021-1675 LPE PoC in Nim (PrintNightmare Local Privilege Escalation)) (December 6, 2021)
- Exploit #6825 - CVE-2021-1675-PrintNightmare (Working PowerShell POC) (October 6, 2021)
- Exploit #6544 - Microsoft-CVE-2021-1675 () (July 19, 2021)
- Exploit #6524 - Print Spooler Remote DLL Injection (July 8, 2021)