Skip to main content

CVE detail

CVE-2021-34481

<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p><strong>UPDATE</strong> August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see <a href="https://support.microsoft.com/help/5005652">KB5005652</a>.</p>

CVSS 8.8 · HighBuzz score 34.0

Buzz score

Why this CVE is surfacing

Buzz score total 34.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • Ransom Cartel, a ransomware-as-a-service (RaaS) operation, has stepped up its attacks over the past year after the disbanding of prominent gangs such as REvil and Conti. Believed to have launched in December 2021, Ransom Cartel has made victims of organizations from among the education, manufacturing, utilities, and energy sectors with aggressive malware and tactics that […]

    newswww.csoonline.comNov 30, 2022, 10:00 AM
  • Microsoft says that Windows will now require admin rights to change the default Point and Print driver installation and update behavior

    newswww.securityweek.comAug 10, 2021, 5:03 PM
  • 19th July – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 19th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches An ongoing Chinese APT espionage campaign tracked as “LuminousMoth” has been targeting entities from Southeast Asia including Mongolia, Myanmar, and the Philippines. Ecuador’s state-run national telecommunication corporation (CNT) has been hit by […]

    vendorresearch.checkpoint.comJul 19, 2021, 4:54 PM
  • Security researchers have unearthed new elevation of privilege (EoP) bugs in Windows Print Spooler, one of the oldest Windows components. Scarce details have been shared about the first one (CVE-2021-34481), aside from the note that it “exists when the Windows Print Spooler service improperly performs privileged file operations,” and can be exploited by an attacker to elevate privilege to SYSTEM level (then run arbitrary code with those privileges). The other (currently without a CVE) is … More →

    newswww.helpnetsecurity.comJul 19, 2021, 9:59 AM
  • Microsoft’s problems with security defects in the Windows Print Spooler utility are getting worse by the week.

    newswww.securityweek.comJul 16, 2021, 5:52 PM
  • Microsoft published guidance to mitigate the impact of a new Windows Print Spooler vulnerability tracked as CVE-2021-34481 that was disclosed today. Microsoft published a security advisory for a new Windows Print Spooler vulnerability, tracked as CVE-2021-34481, that was disclosed on Thursday. The flaw is a privilege elevation vulnerability that resides in the Windows Print Spooler, it was […]

    newssecurityaffairs.comJul 16, 2021, 2:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence