Skip to content
PrintService

PrintService Event ID 808: Spooler plug-in load failed

The print spooler failed to load a plug-in modulePrintService Admin event 808: the spooler failed to load a plug-in or driver DLL. Error 0x45A with an odd DLL path is a PrintNightmare sign.
808
Event ID
808
Channel
Microsoft-Windows-PrintService/Admin
Provider
Microsoft-Windows-PrintService
Log file
Microsoft-Windows-PrintService%4Operational.evtx
Category
Software
Default logging
Logged by default

What event 808 means

Event 808 is written to Microsoft-Windows-PrintService/Admin when the spooler (spoolsv.exe) cannot load a plug-in module such as a printer driver, rendering or configuration DLL. The message gives the DLL path and an error code.

Day to day, it comes from broken or mismatched printer drivers: a missing file (0x7e), a 32/64-bit mismatch (0xc1) and similar. It became a key detection during PrintNightmare (CVE-2021-1675 / CVE-2021-34527): exploits make the spooler load an attacker-supplied DLL as a printer driver, and many payload DLLs are not valid driver plug-ins, so the spooler reports the load as failed — typically with 0x45A — after the DLL's code has already run as SYSTEM.

A DLL under C:\Windows\System32\spool\drivers\x64\3\ with a name that does not belong to any installed driver, or a path on a remote share, is the pattern to look for.

When it is logged

Audit policy / configuration

Microsoft-Windows-PrintService/Admin log, enabled by default.

Successful malicious driver loads may produce no 808 at all; also review the PrintService Operational log (disabled by default) and file creation in the spool drivers folder.

Key fields

FieldWhat it tells you
ErrorCodeWin32 error returned when loading the module.
ValueMeaning
0x45AERROR_DLL_INIT_FAILED — the DLL's initialization routine failed. Typical of payload DLLs loaded through PrintNightmare.
0x7eERROR_MOD_NOT_FOUND — the module or one of its dependencies was not found.
0xc1ERROR_BAD_EXE_FORMAT — not a valid image for this architecture (e.g. 32-bit DLL in a 64-bit spooler).

Common benign sources

  • Old or incompatible printer drivers that fail to load after upgrades.
  • Leftover driver files from removed printers.

What attackers do that produces it

  • PrintNightmare exploitation: a remote or local attacker installs a malicious DLL as a printer driver; the spooler executes it as SYSTEM and logs 808 with 0x45A.
  • Local privilege escalation or lateral movement through the spooler on unpatched hosts.

Investigation tips

  • Check the DLL path in the message; unknown DLL names in the spool drivers folder, user folders or UNC paths are suspicious.
  • Hash and retrieve the DLL; look for its creation (Sysmon 11) and child processes of spoolsv.exe (4688, Sysmon 1).
  • Look for the preceding network logon (4624 type 3) and SMB access to the spooler pipe (5145) to find the source.
  • Confirm the patch level and whether the Print Spooler service is needed on the host (disable it on domain controllers).

MITRE ATT&CK techniques

TechniqueTactics
T1068 Exploitation for Privilege EscalationPrivilege Escalation
T1210 Exploitation of Remote ServicesLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading