CVE-2021-1675

ENISA EUVD: EUVD-2021-7142 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 10 articles Published: 2021-06-08

EPSS Score

Source: FIRST.org · 2026-05-23
94.31%
probability
This CVE has a 94.31% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.8
HIGH
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Temporal
Exploit Code Maturity
Unproven
Remediation Level
Official Fix
Report Confidence
Confirmed
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

CVSS v2 (legacy)

9.3
HIGH
Access Vector
Network
Access Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

NVD
Windows Print Spooler Remote Code Execution Vulnerability

Affected Products

Microsoft
Windows 10 Version 1809
10.0.0
Microsoft
Windows Server 2019
10.0.0
Microsoft
Windows Server 2019 (Server Core installation)
10.0.0
Microsoft
Windows 10 Version 1909
10.0.0
Microsoft
Windows 10 Version 21H1
10.0.0

Exploits & PoC

cube0x0/CVE-2021-1675

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

1983 2021-07-20
calebstewart/CVE-2021-1675

Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)

1099 2021-07-05
hlldz/CVE-2021-1675-LPE

Local Privilege Escalation Edition for CVE-2021-1675/CVE-2021-34527

324 2021-07-05
LaresLLC/CVE-2021-1675

CVE-2021-1675 Detection Info

214 2023-05-20
ly4k/PrintNightmare

Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)

208 2021-10-17
mstxq17/CVE-2021-1675_RDL_LPE

PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR。

145 2021-09-01
sailay1996/PrintNightmare-LPE

CVE-2021-1675 (PrintNightmare)

77 2021-07-05
evilashz/CVE-2021-1675-LPE-EXP

PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527

56 2021-07-02
JumpsecLabs/PrintNightmare

Information on the Windows Spooler vulnerability - CVE-2021-1675; CVE 2021 34527

19 2021-07-12
eversinc33/NimNightmare

CVE-2021-1675 LPE PoC in Nim (PrintNightmare Local Privilege Escalation)

18 2021-12-05
Wra7h/SharpPN

C# PrintNightmare (CVE-2021-1675)

10 2021-09-26
Leonidus0x10/CVE-2021-1675-SCANNER

Vulnerability Scanner for CVE-2021-1675/PrintNightmare

9 2021-07-02
exploitblizzard/PrintNightmare-CVE-2021-1675

Youtube : https://youtu.be/Zr0KjYDSFKQ

5 2021-07-04
hahaleyile/my-CVE-2021-1675

see https://github.com/cube0x0/CVE-2021-1675

3 2021-08-13
yu2u/CVE-2021-1675

CVE-2021-1675 exploit

2 2021-06-29
ozergoker/PrintNightmare

Windows Print Spooler Service RCE CVE-2021-1675 (PrintNightmare)

2 2021-07-03
peckre/PNCVE-Win10-20H2-Exploit

A one-click script to gain a System privileges command line in Windows 10 20H2 that exploits CVE-2021-1675

1 2024-01-17
tanarchytan/CVE-2021-1675

Fix without disabling Print Spooler

0 2021-07-02
kougyokugentou/CVE-2021-1675

A small powershell script to disable print spooler service using desired state configuration

0 2021-07-02
ptter23/CVE-2021-1675

CVE-2021-1675: ZERO-DAY VULNERABILITY IN WINDOWS PRINTER SERVICE WITH AN EXPLOIT AVAILABLE IN ALL OPERATING SYSTEM VERSIONS

0 2021-07-02
initconf/cve-2021-1675-printnightmare

to catch cve-2021-1675-printnightmare

0 2021-07-03
galoget/PrintNightmare-CVE-2021-1675-CVE-2021-34527

CVE-2021-1675 / CVE-2021-34527 - PrintNightmare Python, C# and PowerShell Exploits Implementations (LPE & RCE)

0 2021-07-12
r1skkam/PrintNightmare

Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527)

0 2022-12-29
0xSs0rZ/Windows_Exploit

CVE-2021-1675/CVE-2021-34527 PrintNightmare & CVE-2020-0668

0 2024-06-05
CameraShutterBug/PrintNightmare

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

0 2025-07-24
ccordeiro/CVE-2021-1675

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

0 2025-11-19
45 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
75%
EPSS 94.31%
CVSS v3.1 7.8
Mentions 10
Last Seen Nov 09, 2021

CNA Information

CNA Assigner
microsoft
CNA Title
Windows Print Spooler Remote Code Execution Vulnerability

Analyst Note

CVE-2021-1675 is the PrintNightmare Windows Print Spooler RCE vulnerability. Published June 8, 2021, it was actively exploited in the wild before Microsoft released patches on June 8 and subsequent updates. The vulnerability became widely documented as a zero-day with proof-of-concept exploitation occurring before official patches were fully deployed, meeting the core zero-day criteria despite limited article coverage in this dataset.

Threat Actors 9

Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT32
apt_group Information theft and espionage 🇻🇳 VN
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
Hacking Team
apt_group 🇮🇹 IT
Earth Lamia
apt_group Information theft and espionage 🇨🇳 CN
WildPressure
apt_group Information theft and espionage UNKNOWN
APT 5
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026
Published DateJun 08, 2021