CVE-2021-1675 Print Spooler Exploitation IPC Access
Description
Detects remote printer driver load from Detailed File Share in Security logs that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675 and CVE-2021-34527
Query · sigma
selection: EventID: 5145 ShareName: \\\\\*\\IPC$ RelativeTargetName: spoolss AccessMask: '0x3' ObjectType: File condition: selection
Known false positives
- Unknown