Security Research

CVE-2021-34527 PrintNightmare: A SYSTEM-Level DLL Loading Trap in Windows Print Spooler

#Vulnerability Analysis#Code Audit#Malware
Print Spooler loads a SYSTEM-level malicious DLL from an SMB share

A DLL-loading control gap in the Windows Print Spooler service — a single crafted SMB share is enough to coerce the system into loading an attacker-supplied driver DLL and handing the attacker SYSTEM-level command execution.

Unlock to view this content.