← voltar
CVE-2021-1675

Windows Print Spooler Remote Code Execution Vulnerability

CVSS 7.8 HIGHEPSS 86.1%● KEV
Em resumo

Uma falha no Serviço de Fila de Impressão do Windows permite que atacantes executem código malicioso remotamente em um computador sem precisar de permissões especiais. O atacante pode explorar isso enviando requisições malformadas ao serviço de impressão, potencialmente tomando controle total do sistema afetado.

Detalhe técnico

O serviço Windows Print Spooler não valida adequadamente requisições de clientes, permitindo execução remota de código não autenticada através da interface RPC. Um atacante pode enviar um trabalho de impressão malicioso ou chamada RPC que dispara execução de código arbitrário com privilégios SYSTEM, exigindo apenas acesso de rede à porta 445 ou endpoints similares de serviço de impressão.

Resumo gerado e traduzido por IA a partir da descrição oficial.
Windows Print Spooler Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
PoCs públicas encontradas48
githubgithub.com/cube0x0/CVE-2021-16751990githubgithub.com/calebstewart/CVE-2021-16751100githubgithub.com/hlldz/CVE-2021-1675-LPE325githubgithub.com/LaresLLC/CVE-2021-1675214githubgithub.com/ly4k/PrintNightmare209githubgithub.com/mstxq17/CVE-2021-1675_RDL_LPE145githubgithub.com/sailay1996/PrintNightmare-LPE77githubgithub.com/evilashz/CVE-2021-1675-LPE-EXP56githubgithub.com/cybersecurityworks553/CVE-2021-1675_PrintNightMare23githubgithub.com/JumpsecLabs/PrintNightmare19githubgithub.com/eversinc33/NimNightmare18githubgithub.com/k8gege/cve-2021-167515githubgithub.com/Wra7h/SharpPN10githubgithub.com/Leonidus0x10/CVE-2021-1675-SCANNER9githubgithub.com/corelight/CVE-2021-16759githubgithub.com/exploitblizzard/PrintNightmare-CVE-2021-16755githubgithub.com/thomasgeens/CVE-2021-16753githubgithub.com/hahaleyile/my-CVE-2021-16753githubgithub.com/bartimusprimed/CVE-2021-1675-Yara2githubgithub.com/ozergoker/PrintNightmare2githubgithub.com/kondah/patch-cve-2021-16752githubgithub.com/yu2u/CVE-2021-16752githubgithub.com/killtr0/CVE-2021-1675-PrintNightmare2githubgithub.com/DLL00P/CVE-2021-16751githubgithub.com/puckiestyle/CVE-2021-16751githubgithub.com/Winter3un/CVE-2021-16751githubgithub.com/OppressionBreedsResistance/CVE-2021-1675-PrintNightmare1githubgithub.com/peckre/PNCVE-Win10-20H2-Exploit1githubgithub.com/whoami-chmod777/CVE-2021-1675-CVE-2021-345271githubgithub.com/galoget/PrintNightmare-CVE-2021-1675-CVE-2021-345270githubgithub.com/zha0/Microsoft-CVE-2021-16750githubgithub.com/whoami-chmod777/CVE-2021-1675---PrintNightmare-LPE-PowerShell-0githubgithub.com/kougyokugentou/CVE-2021-16750githubgithub.com/mrezqi/CVE-2021-1675_CarbonBlack_HuntingQuery0githubgithub.com/tanarchytan/CVE-2021-16750githubgithub.com/initconf/cve-2021-1675-printnightmare0githubgithub.com/ptter23/CVE-2021-16750githubgithub.com/thalpius/microsoft-cve-2021-16750githubgithub.com/0xSs0rZ/Windows_Exploit0githubgithub.com/r1skkam/PrintNightmare0githubgithub.com/000Tonio/cve-2021-16750githubgithub.com/Sp4ceDogy/NPE-CS-V-CVE-2021-16750githubgithub.com/CameraShutterBug/PrintNightmare0githubgithub.com/ccordeiro/CVE-2021-16750githubgithub.com/edsonjt81/CVE-2021-16750cve_referencepacketstormsecurity.com/files/167261/Print-Spooler-Remote-DLL-Injection.htmlnão verificadocve_referencepacketstormsecurity.com/files/163349/Microsoft-PrintNightmare-Proof-Of-Concept.htmlnão verificadocve_referencepacketstormsecurity.com/files/163351/PrintNightmare-Windows-Spooler-Service-Remote-Code-Execution.htmlnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →