MSRC compact vulnerability detail

CVE-2021-34481 · Windows Print Spooler Remote Code Execution Vulnerability

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

Severity
Important
Impact
Remote Code Execution
CVSS
8.8 base · 8.2 temporal
Release
2021-07-15
Signals
Windows Print Spooler Components Remote Code Execution Exploited: No Publicly disclosed: Yes Exploitability: Exploitation More Likely
CWE
No CWE data published.
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.
FAQ / Articles
FAQ
Why did the security impact change from elevation of privilege to remote code execution? We became aware of a remote attack scenario for this vulnerability and revised our assessment accordingly. Did the July 2021 security update introduce this vulnerability? No, the vulnerability existed before the July 13, 2021 security update. We recommend that Microsoft customers install the latest security updates. Why did the Point and Print default behavior change? Please see KB5005652.