LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-1675: Microsoft Windows Print Spooler Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-1675 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

CVE-2021-1675 is a remote code execution vulnerability in the Microsoft Windows Print Spooler. It allows an attacker who can reach the service to run code in the context of the spooler process. CISA notes that this issue has been used in ransomware activity, so organizations that still run the Print Spooler on domain controllers, print servers, or workstations should treat it as a priority.

Public detail on exact mechanics is limited; defenders should confirm affected builds, patch identifiers, and any configuration caveats directly against the Microsoft advisory.

How it works

The underlying weakness is classified as CWE-285 (Improper Authorization). In the Print Spooler, this means the service does not adequately enforce authorization checks on certain operations that an authenticated or, in some configurations, remote caller can invoke. An attacker who can interact with the spooler abuses that gap to cause the service to load or execute attacker-controlled content, resulting in code execution under the spooler’s privileges.

Because the spooler traditionally runs with elevated rights and is reachable over the network when printer sharing or remote printing is enabled, successful abuse can give the attacker a foothold for lateral movement or payload deployment. Exact call sequences and preconditions are not detailed in the supplied facts; treat any public proof-of-concept material as untrusted until validated against the vendor’s description.

Am I affected? How to find it in your systems

The Print Spooler is present by default on most Windows client and server installations. It is commonly enabled on print servers, domain controllers that also host printing, and end-user workstations that share printers or accept remote print jobs.

How to remediate

Apply the security updates Microsoft released for this vulnerability, following the vendor’s installation order and reboot guidance. CISA’s required action is simply to apply updates per vendor instructions; that remains the primary fix.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not replace the official patch; schedule the update as soon as operationally possible.

If your data may have been exposed

Because this vulnerability has been observed in ransomware campaigns, successful exploitation can lead to broader compromise and data theft. If you have indicators of exploitation or find unpatched systems that were internet-reachable or broadly accessible, initiate your incident-response process: isolate affected hosts, preserve volatile evidence, and hunt for persistence and lateral movement. As a quick external check, users can run a free exposure scan of their email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps, then force password resets and enable multi-factor authentication where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-285
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities