kevmap

Coverage › CVE-2021-1675

CVE-2021-1675 Unmapped

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Vendor / product
Microsoft — Windows
Description (CISA)
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
Added to KEV
2021-11-03
Due date
2021-11-17
Required action
Apply updates per vendor instructions.
Known ransomware use
Known
CWE
CWE-285
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2021-1675
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques

No public source states how this vulnerability is exploited in ATT&CK terms.

The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2021-1675. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-285) — here is why — and does not guess.

This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.

Sigma rules tagged with this CVE

10 rules in SigmaHQ carry the tag cve.2021-1675. These are shown as detection content for the CVE itself. Their ATT&CK tags are deliberately not rendered here: a rule author's tag is not an authoritative statement of how the vulnerability is exploited, and this page does not show techniques for unmapped entries.

Author: FPT.EagleEye, Thomas Patzke (improvements) · 2021-06-29 (modified 2022-06-02) · logsource: product=windows category=image_load · 02fb90de-c321-4e63-a6b9-25f4b03dfd14
Detect DLL Load from Spooler Service backup folder. This behavior has been observed during the exploitation of the Print Spooler Vulnerability CVE-2021-1675 and CVE-2021-34527 (PrinterNightmare).
CVE tags: CVE-2021-1675CVE-2021-34527
Author: Florian Roth (Nextron Systems) · 2021-06-29 (modified 2022-12-25) · logsource: product=windows category=file_event · 2131cfb3-8c12-45e8-8fa0-31f5924e9f07
Detects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
CVE tags: CVE-2021-1675
Author: Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Tim Shelton · 2021-06-30 (modified 2022-11-15) · logsource: product=windows service=printservice-admin · 4e64668a-4da1-49f5-a8df-9e2d5b866718
Detects events of driver load errors in print service logs that could be a sign of successful exploitation attempts of print spooler vulnerability CVE-2021-1675
CVE tags: CVE-2021-1675
Author: Bhabesh Raj · 2021-07-01 (modified 2023-02-17) · logsource: product=windows category=file_delete · 5b2bbc47-dead-4ef7-8908-0cf73fcbecbf
Detect DLL deletions from Spooler Service driver folder. This might be a potential exploitation attempt of CVE-2021-1675
CVE tags: CVE-2021-1675
Author: Sittikorn S, Nuttakorn T, Tim Shelton · 2021-07-01 (modified 2023-10-23) · logsource: category=antivirus · 6fe1719e-ecdf-4caf-bffe-4f501cb0a561
Detects the suspicious file that is created from PoC code against Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527 (PrinterNightmare), CVE-2021-1675 .
CVE tags: CVE-2021-34527CVE-2021-1675
Author: @neu5ron (Nate Guagenti) · 2021-08-23 (modified 2025-11-03) · logsource: product=zeek service=dce_rpc · 7b33baef-2a75-4ca3-9da4-34f9a15382d8
Detects the remote installation of a print driver which is possible indication of the exploitation of PrintNightmare (CVE-2021-1675). The occurrence of print drivers being installed remotely via RPC functions should be rare, as print drivers are normally installed locally and or through group policy.
CVE tags: CVE-2021-1678CVE-2021-1675CVE-2021-34527
Author: INIT_6 · 2021-07-02 (modified 2022-10-05) · logsource: product=windows service=security · 8fe1c584-ee61-444b-be21-e9054b229694
Detects remote printer driver load from Detailed File Share in Security logs that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675 and CVE-2021-34527
CVE tags: CVE-2021-1675CVE-2021-34527
Author: Markus Neis, @markus_neis, Florian Roth · 2021-07-04 (modified 2023-06-12) · logsource: product=windows category=registry_event · ba6b9e43-1d45-4d3c-a504-1043a64c8469
Detects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527
CVE tags: CVE-2021-1675CVE-2021-34527
Author: Florian Roth (Nextron Systems) · 2020-07-01 (modified 2023-08-17) · logsource: product=windows category=registry_set · e0813366-0407-449a-9869-a2db1119dc41
Detects a suspicious printer driver installation with an empty Manufacturer value
CVE tags: CVE-2021-1675
Author: Florian Roth (Nextron Systems) · 2021-07-01 (modified 2022-10-09) · logsource: product=windows service=printservice-operational · f34d942d-c8c4-4f1f-b196-22471aecf10a
Detects driver load events print service operational log that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675
CVE tags: CVE-2021-1675