CVE-2021-34481

HIGH EXPLOITED RANSOMWARE

Windows Print Spooler - Remote Code Execution via Privileged File Operations

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-34481 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including vpn28.

AI-analyzed exploit summary The repository contains a PowerShell script that checks for the presence of specific Windows hotfixes related to CVE-2021-34481 (Windows Print Spooler RCE). It does not exploit the vulnerability but scans for patches.

Description

<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p><strong>UPDATE</strong> August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see <a href="https://support.microsoft.com/help/5005652">KB5005652</a>.</p>

Exploits (1)

nomisec SCANNER 2 stars
by vpn28 · poc
https://github.com/vpn28/CVE-2021-34481

The repository contains a PowerShell script that checks for the presence of specific Windows hotfixes related to CVE-2021-34481 (Windows Print Spooler RCE). It does not exploit the vulnerability but scans for patches.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Windows Print Spooler
Auth required
Prerequisites: Local or remote access to a Windows system with PowerShell execution privileges
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.4478
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-11-30
Ransomware Use Confirmed
CWE
CWE-269
Status published
Products (16)
microsoft/windows_10
microsoft/windows_10 20h2
microsoft/windows_10 21h1
microsoft/windows_10 1607
microsoft/windows_10 1809
microsoft/windows_10 1909
microsoft/windows_10 2004
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 6 more
Published Jul 16, 2021
Tracked Since Feb 18, 2026