Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation

Looks for Print Spooler plug-in/module load errors in Windows logs that may indicate CVE-2021-1675 exploitation attempts.

FreeReviewedSigma · High · v5
Product
windows
Service
printservice-admin
Author
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Tim Shelton (SigmaHQ), DRL 1.1
Published
2021-06-30
Updated
2026-07-31

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows print service (PrintServiceAdmin) events where the print spooler reports driver load or plugin-module load failures with specific error codes, and where log text matches known plugin failure wording. These errors can indicate an attempt to exploit the print spooler vulnerability associated with CVE-2021-1675, including attempts to load malicious DLLs. It relies on telemetry from printservice-admin logs, specifically EventID 808, error codes, and keyword strings describing failed module/plugin loading.

Related detections6 linkedT1569 — drag to rearrange
Obfuscated Massive Service Failures - Tchopper (via system)
Malicious Massive Remote Service Creation via Named Pipes - TChopper, CME (via security)
Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)
KrbRelayUp Service Installation - Native (via system)
Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)
Windows PsExec Execution Triggered by psexec.exe Process Creation
Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Pivot detection · T1569 · 6 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.