Skip to main content
Room Banner
Back to all walkthroughs
Room Icon

PrintNightmare

Max room.

Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527).

medium

30 min

12,103

User profile photo.

To access material, start machines and answer questions login.

This room will cover the Printnightmare vulnerability from a offensive and defensive perspective.

Per Microsoft, "A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights".

Learning Objectives: In this room, you will learn what PrintNightmare vulnerability is, how to exploit and mitigate it. You will also learn the detection mechanisms using Windows Event Logs and Wireshark. 

Outcome: As a result, you will be ready to defend your organization against any potential PrintNightmare attacks. 

Learning Pre-requisites: You should be familiar with Wireshark, Windows Event Logs, Fundamentals, and prior to joining this room. 
Answer the questions below
Read the above.