PT-2021-3528 · Microsoft · Windows Print Spooler+1
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Print Spooler (affected versions not specified)
Description
A remote code execution flaw exists in the Windows Print Spooler service due to improper privileged file operations and access control deficiencies. An attacker with low privileges can execute arbitrary code with SYSTEM privileges by spoofing print jobs or loading a malicious DLL library. Successful exploitation allows the attacker to install programs, view, modify, or delete data, and create new accounts with full user rights. This issue has been utilized in ransomware attacks.
Recommendations
Disable the Print Spooler service on non-print servers.
Enforce the use of signed drivers.
Monitor Active Directory for suspicious activity.
Exploit
Fix
RCE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Print Spooler