CVE-2021-36958 HIGH

CVE-2021-36958: Windows Print Spooler Remote Code Execution Vulnerability

Vendor Microsoft
Product Windows 10 Version 1809
Published August 12, 2021
Last update August 4, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

What the vulnerability does

01Description

<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p>

Key dates

02Disclosure timeline

August 12, 2021 CVE published
August 4, 2024 Record updated