> Source: [sk174387](https://support.checkpoint.com/results/sk/sk174387)

# sk174387 -  Check Point response to PrintNightmare vulnerability

| Property | Value |
|----------|-------|
| Solution ID | sk174387 |
| Date Created | 2021-07-08 |
| Last Modified | 2021-07-09 |
| Technical Level | General |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, R82.20, R82.10, R82, R81.20 |

## Symptoms

- On July 6, 2021, Microsoft announced the release of an out-of-band patch for a Windows Print Spooler service vulnerability, called PrintNightmare. The update came following availability of a public proof of concept for CVE-2021-1675. Another CVE, CVE-2021-34527, was assigned to a remotely exploitable vulnerability of similar nature.

## Solution

Check Point provides security coverage to the PrintNightmare vulnerabilities with the following Threat Prevention protections:  

* **IPS**Windows Print Spooler Remote Code Execution (CVE-2021-34527)

<!-- -->

* **Threat Emulation**   
  Exploit.Wins.PrintNightmare.A

<!-- -->

* **Harmony Endpoint**   
  HEUR:Exploit.Win32.CVE-2021-1675.a  
  HEUR:Trojan-Dropper.Win32.Pegazus.gen  
  PDM:Exploit.Win32.Generic  
  PDM:Trojan.Win32.Generic

<br />

<br />

<br />

Microsoft have provided additional workarounds for the vulnerability in a relevant [advisory.](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527)

```

```

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
