PT-2021-3528 · Microsoft · Windows Print Spooler+1

·

CVE-2021-34527

·

Published

2021-06-28

·

Updated

2026-07-08

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Print Spooler (affected versions not specified)
Description A remote code execution flaw exists in the Windows Print Spooler service due to improper privileged file operations and access control deficiencies. An attacker with low privileges can execute arbitrary code with SYSTEM privileges by spoofing print jobs or loading a malicious DLL library. Successful exploitation allows the attacker to install programs, view, modify, or delete data, and create new accounts with full user rights. This issue has been utilized in ransomware attacks.
Recommendations Disable the Print Spooler service on non-print servers. Enforce the use of signed drivers. Monitor Active Directory for suspicious activity.

Exploit

Fix

RCE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03578
CVE-2021-34527
MICROSOFTWINDOWSCVE2021_34527

Affected Products

Windows
Windows Print Spooler