

PrintNightmare out-of-band update also for Windows Server 20 (July 7, 2021) Out-of-Band Update closes Windows PrintNightmare Vulnerability (July 6, 2021) Then, as of July 6 and 7, 2021, Microsoft released unscheduled updates for supported versions of Windows (see articles below). I had reported early on the vulnerability in the blog post PoC for Windows Print Spooler Vulnerability Public, High RCE Risk.

Through an unintentionally published proof of concept (PoC), there have already been initial attacks on the vulnerability. These vulnerabilities allow attackers to execute arbitrary code with SYSTEM privileges. Remote Code Execution (RCE) vulnerability CVE-2021-1675 (as well as other vulnerabilities) exists in the Windows Print Spooler service in all versions of Windows.
