CVE-2021-34527: PrintNightmare
What is PrintNightmare?
A privilege escalation and RCE vulnerability in the Windows Print Spooler service. Authenticated attackers can execute code with SYSTEM privileges by installing a malicious printer driver — remotely or locally.
Impact & Exploitation
Affected every Windows system with Print Spooler enabled (nearly all). Exploit was accidentally disclosed by researchers. Enabled privilege escalation to SYSTEM on any domain-joined machine.
How Precogs AI Detects PrintNightmare
Precogs AI Binary SAST detects Print Spooler dependencies in compiled Windows applications and identifies privilege escalation vectors through driver installation mechanisms.