CVE detail
CVE-2021-34481
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p><strong>UPDATE</strong> August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see <a href="https://support.microsoft.com/help/5005652">KB5005652</a>.</p>
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
Ransom Cartel, a ransomware-as-a-service (RaaS) operation, has stepped up its attacks over the past year after the disbanding of prominent gangs such as REvil and Conti. Believed to have launched in December 2021, Ransom Cartel has made victims of organizations from among the education, manufacturing, utilities, and energy sectors with aggressive malware and tactics that […]
newswww.csoonline.comNov 30, 2022, 10:00 AMMicrosoft says that Windows will now require admin rights to change the default Point and Print driver installation and update behavior
newswww.securityweek.comAug 10, 2021, 5:03 PM- 19th July – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 19th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches An ongoing Chinese APT espionage campaign tracked as “LuminousMoth” has been targeting entities from Southeast Asia including Mongolia, Myanmar, and the Philippines. Ecuador’s state-run national telecommunication corporation (CNT) has been hit by […]
vendorresearch.checkpoint.comJul 19, 2021, 4:54 PM - There are new unpatched bugs in Windows Print SpoolerHelp Net Security
Security researchers have unearthed new elevation of privilege (EoP) bugs in Windows Print Spooler, one of the oldest Windows components. Scarce details have been shared about the first one (CVE-2021-34481), aside from the note that it “exists when the Windows Print Spooler service improperly performs privileged file operations,” and can be exploited by an attacker to elevate privilege to SYSTEM level (then run arbitrary code with those privileges). The other (currently without a CVE) is … More →
newswww.helpnetsecurity.comJul 19, 2021, 9:59 AM Microsoft’s problems with security defects in the Windows Print Spooler utility are getting worse by the week.
newswww.securityweek.comJul 16, 2021, 5:52 PM- Microsoft alerts about a new Windows Print Spooler vulnerabilitySecurity Affairs
Microsoft published guidance to mitigate the impact of a new Windows Print Spooler vulnerability tracked as CVE-2021-34481 that was disclosed today. Microsoft published a security advisory for a new Windows Print Spooler vulnerability, tracked as CVE-2021-34481, that was disclosed on Thursday. The flaw is a privilege elevation vulnerability that resides in the Windows Print Spooler, it was […]
newssecurityaffairs.comJul 16, 2021, 2:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-35768CVSS 7.8 · High
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2022-34706CVSS 7.8 · High
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
- CVE-2022-34691CVSS 8.8 · High
Active Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2022-23296CVSS 7.8 · High
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-42285CVSS 7.8 · High
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2021-41377CVSS 7.8 · High
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability