cbcvebase.
CVE-2021-34481
published 2021-07-16

CVE-2021-34481: A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who…

PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
45.42%
98.7th percentile
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.0 < 10.0.10240.1902210.0.10240.19022
microsoftwindows_10_version_1607>= 10.0.0 < 10.0.14393.458310.0.14393.4583
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.211410.0.17763.2114
microsoftwindows_10_version_1909>= 10.0.0 < 10.0.18363.173410.0.18363.1734
microsoftwindows_10_version_2004>= 10.0.0 < 10.0.19041.116510.0.19041.1165
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.116510.0.19042.1165
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.116510.0.19043.1165
microsoftwindows_7>= 6.1.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.200946.3.9600.20094
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < 6.1.7601.256856.1.7601.25685
microsoftwindows_server_2008_service_pack_2>= 6.0.0 < 6.0.6003.211926.0.6003.21192
microsoftwindows_server_2012>= 6.2.0 < 6.2.9200.234356.2.9200.23435
microsoftwindows_server_2012_r2>= 6.3.0 < 6.3.9600.200946.3.9600.20094
microsoftwindows_server_2016
microsoftwindows_server_2016>= 10.0.0 < 10.0.14393.458310.0.14393.4583
microsoftwindows_server_2019>= 10.0.0 < 10.0.17763.211410.0.17763.2114

Detection & IOCsextracted from sources · hover to see the quote

port4444
  • Monitor Windows PrintService event log for Event ID 316 — logged for both successful and unsuccessful printer driver add/update attempts (Stage 0 indicator).
  • Detect IPS/network events for unencrypted SMBv1 or SMBv2 traffic associated with MS-RPRN or MS-PAR PrintNightmare implementations.
  • Enable Microsoft-Windows-PrintService/Operational logging via PowerShell to capture exploitation attempts if not already enabled.
  • ·The Print Spooler service is not disabled by default on most machines including domain controllers and print servers, making them broadly exposed to network-based exploitation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.