Skip to main content

Overview

CVE-2021-34527. Load malicious DLL via Print Spooler service. Variants: RCE (remote) and LPE (local privilege escalation).

Check Spooler Running


RCE — Remote

Host DLL

Exploit


LPE — Local Privilege Escalation

Adds local admin user.

Mimikatz Method


Quick Reference