finds.dev← search

// the find

JohnHammond/CVE-2021-34527

★ 324 · PowerShell · updated Jul 2021

A PowerShell implementation of the PrintNightmare local privilege escalation exploit (CVE-2021-34527), ported from the earlier Python/C++ PoCs so you don't need a second toolchain to pop a local admin on vulnerable Windows Server 2016/2019 boxes. Built for pentesters and red teamers who need an LPE primitive during an engagement, not for anyone running production infrastructure.

Pure PowerShell with no external dependencies beyond what's embedded in the script, so it drops onto a box without needing Python or compiling anything on target. The DLL payload is Base64/GZIP-embedded and patched at runtime, and `-DLL` lets you swap in your own payload instead of the default add-admin-user behavior, which makes it usable as a generic LPE delivery mechanism rather than a one-trick demo. Reuses proven primitives from PowerSploit's PowerUp for the Win32 API access instead of reinventing reflection code.

No error handling or OPSEC considerations at all — it grabs the first printer driver it finds rather than searching for the right one, which the README admits, so it can fail or behave unpredictably against non-default driver configurations. Single flat script with no tests, no CI, and no indication the DLL source was rebuilt or re-verified after the 2021-07-02 push, so you're trusting a 4+ year old embedded binary blob. Zero maintenance since release: no patches for detection changes, no updates for newer Windows builds, and the repo is explicitly a reskin of calebstewart/CVE-2021-1675, so there are now two near-identical unmaintained copies of the same code to find.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →