An accidentally published proof-of-concept exploit exposed the Windows Print Spooler flaw known as PrintNightmare, showing that authenticated users could achieve remote code execution as SYSTEM, including on Active Directory domain controllers where the Print Spooler service was often enabled by default. The bug was tied to CVE-2021-1675, which Microsoft had initially treated as a privilege-escalation issue before reclassifying it as remote code execution, prompting warnings that ransomware operators could quickly weaponize the vulnerability and that even fully patched Windows Server 2019 domain controllers might remain at risk until a dedicated fix arrived.
Microsoft responded with the KB5004945 emergency security update for supported Windows versions, but the patch caused widespread printer connectivity failures, with Zebra label printers among the most visible affected devices and reports indicating other brands were also impacted. Microsoft acknowledged the printing issue as a known problem and advised affected users to either remove the update or reinstall printers with administrative credentials, while earlier mitigation guidance for the underlying threat had urged organizations to disable the Print Spooler service on domain controllers and other critical servers until a more complete remediation was available.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
By 2021-08-12, Cisco Talos reported that the Vice Society ransomware group was exploiting the PrintNightmare vulnerability to gain access during real-world attacks. The report marked a shift from vulnerability disclosure and patching to documented use by a named ransomware actor.
Microsoft published guidance for KB5005652 describing new default Point and Print driver installation behavior associated with CVE-2021-34481. The advisory documented stricter administrative requirements for printer driver installation as part of Print Spooler security hardening.
On 2021-07-08, Microsoft recognized the printer breakage as a known issue and suggested rollback or reinstalling printers with administrative credentials, while Zebra said multiple brands were affected and that Microsoft planned an updated fix within one to two business days.
After users installed KB5004945, some systems lost the ability to connect to printers, with several Zebra label printer models specifically reported as affected.
By 2021-07-08, Microsoft had issued the KB5004945 security update to address the actively exploited PrintNightmare vulnerability across supported Windows versions.
By 2021-06-30, experts warned that fully patched Windows Server 2019 domain controllers could still be exploitable because the Print Spooler service was enabled by default, and advised disabling the service on critical systems.
Researchers at Sangfor Technologies mistakenly released proof-of-concept exploit code after believing the bug had been fixed, exposing details of the unpatched Print Spooler flaw later dubbed PrintNightmare.
On 2021-06-21, Microsoft updated its assessment of CVE-2021-1675 and reclassified the Print Spooler bug as a remote code execution vulnerability.
On 2021-06-08, Microsoft released a patch for CVE-2021-1675, initially describing the Windows Print Spooler issue as a local privilege-escalation vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
support.microsoft.com
Open sourcegithub.com
Open sourceblog.talosintelligence.com
Open sourceindependent.co.uk
Open sourcebbc.com
Open sourceus-cert.cisa.gov
Open sourceforbes.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.