PT-2021-3629 · Microsoft · Windows Print Spooler+1

Jacob Baines

·

Published

2021-07-07

·

Updated

2024-01-31

·

CVE-2021-34481

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Print Spooler versions prior to the version with the security update released by Microsoft
Description The issue is related to insufficient access restrictions in the Windows Print Spooler service, allowing a remote attacker to execute arbitrary code with SYSTEM privileges by loading a malicious DLL library. This could enable the attacker to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Windows Print Spooler versions prior to the version with the security update released by Microsoft: Install the security updates provided by Microsoft immediately to address this issue. Additionally, consider changing the Point and Print default behavior as described in KB5005652. As a temporary workaround, consider restricting access to the Windows Print Spooler service until the security update is applied.

Fix

RCE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-03828
CVE-2021-34481

Affected Products

Windows
Windows Print Spooler