PT-2021-3629 · Microsoft · Windows Print Spooler+1
Jacob Baines
·
Published
2021-07-07
·
Updated
2024-01-31
·
CVE-2021-34481
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Print Spooler versions prior to the version with the security update released by Microsoft
Description
The issue is related to insufficient access restrictions in the Windows Print Spooler service, allowing a remote attacker to execute arbitrary code with SYSTEM privileges by loading a malicious DLL library. This could enable the attacker to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Windows Print Spooler versions prior to the version with the security update released by Microsoft:
Install the security updates provided by Microsoft immediately to address this issue.
Additionally, consider changing the Point and Print default behavior as described in KB5005652.
As a temporary workaround, consider restricting access to the Windows Print Spooler service until the security update is applied.
Fix
RCE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Print Spooler