CVE-2021-34481
HIGH EXPLOITED RANSOMWAREWindows Print Spooler - Remote Code Execution via Privileged File Operations
Title source: llmExploitation Summary
CVE-2021-34481 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including vpn28.
AI-analyzed exploit summary The repository contains a PowerShell script that checks for the presence of specific Windows hotfixes related to CVE-2021-34481 (Windows Print Spooler RCE). It does not exploit the vulnerability but scans for patches.
Description
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p><strong>UPDATE</strong> August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see <a href="https://support.microsoft.com/help/5005652">KB5005652</a>.</p>
Exploits (1)
The repository contains a PowerShell script that checks for the presence of specific Windows hotfixes related to CVE-2021-34481 (Windows Print Spooler RCE). It does not exploit the vulnerability but scans for patches.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H