SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34481

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations.

HIGH 8.8EPSS 47.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 47.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
47.72% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
microsoft/windows 10 · microsoft/windows 7 · microsoft/windows 8.1 · microsoft/windows rt 8.1 · microsoft/windows server 2008 · microsoft/windows server 2012 · microsoft/windows server 2016 · microsoft/windows server 2019
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.