Important CVSS 8.8 📢 Publicly disclosed 2021-07 archive

Executive Summary

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.

Overview

8.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Jul 13 2021
Last Updated Jul 13 2021
Publicly Disclosed Yes
CISA KEV Not Listed
Known Exploits None Known
NVD CVSS 8.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Functional
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 8.2

EPSS Score

No EPSS score available for this CVE.

View on FIRST.org

Affected Products

53 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1809 for 32-bit Systems 5005030 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for x64-based Systems 5005030 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1809 for ARM64-based Systems 5005030 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 5005030 (Security Update) Important Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 5005030 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1909 for 32-bit Systems 5005031 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1909 for x64-based Systems 5005031 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1909 for ARM64-based Systems 5005031 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H1 for x64-based Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H1 for ARM64-based Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 21H1 for 32-bit Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 2004 for 32-bit Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 2004 for ARM64-based Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 2004 for x64-based Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows Server, version 2004 (Server Core installation) 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 20H2 for 32-bit Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 20H2 for ARM64-based Systems 5005033 (Security Update) Important Remote Code Execution Yes
Windows Server, version 20H2 (Server Core Installation) 5005033 (Security Update) Important Remote Code Execution Yes
Windows 10 for 32-bit Systems 5005040 (Security Update) Important Remote Code Execution Yes
Windows 10 for x64-based Systems 5005040 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for 32-bit Systems 5005043 (Security Update) Important Remote Code Execution Yes
Windows 10 Version 1607 for x64-based Systems 5005043 (Security Update) Important Remote Code Execution Yes
Windows Server 2016 5005043 (Security Update) Important Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 5005043 (Security Update) Important Remote Code Execution Yes
Windows 7 for 32-bit Systems Service Pack 1 5005088 (Monthly Rollup) Important Remote Code Execution Yes
Windows 7 for x64-based Systems Service Pack 1 5005088 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2008 R2 for x64-based Systems Service Pack 1 5005088 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5005088 (Monthly Rollup) Important Remote Code Execution Yes
Windows 7 for 32-bit Systems Service Pack 1 5005089 (Security Only) Important Remote Code Execution Yes
Windows 7 for x64-based Systems Service Pack 1 5005089 (Security Only) Important Remote Code Execution Yes
Windows Server 2008 R2 for x64-based Systems Service Pack 1 5005089 (Security Only) Important Remote Code Execution Yes
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5005089 (Security Only) Important Remote Code Execution Yes
Windows 8.1 for 32-bit systems 5005076 (Monthly Rollup) Important Remote Code Execution Yes
Windows 8.1 for x64-based systems 5005076 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 5005076 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 R2 (Server Core installation) 5005076 (Monthly Rollup) Important Remote Code Execution Yes
Windows 8.1 for 32-bit systems 5005106 (Security Only) Important Remote Code Execution Yes
Windows 8.1 for x64-based systems 5005106 (Security Only) Important Remote Code Execution Yes
Windows Server 2012 R2 5005106 (Security Only) Important Remote Code Execution Yes
Windows Server 2012 R2 (Server Core installation) 5005106 (Security Only) Important Remote Code Execution Yes
Windows RT 8.1 5005076 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5005090 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5005090 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2008 for x64-based Systems Service Pack 2 5005090 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5005090 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 5005095 (Security Only) Important Remote Code Execution Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5005095 (Security Only) Important Remote Code Execution Yes
Windows Server 2008 for x64-based Systems Service Pack 2 5005095 (Security Only) Important Remote Code Execution Yes
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5005095 (Security Only) Important Remote Code Execution Yes
Windows Server 2012 5005099 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 (Server Core installation) 5005099 (Monthly Rollup) Important Remote Code Execution Yes
Windows Server 2012 5005094 (Security Only) Important Remote Code Execution Yes
Windows Server 2012 (Server Core installation) 5005094 (Security Only) Important Remote Code Execution Yes

Patches

13 patches
Article Type Restart
5005030 Security Update Yes
5005031 Security Update Yes
5005033 Security Update Yes
5005040 Security Update Yes
5005043 Security Update Yes
5005088 Monthly Rollup Yes
5005089 Security Only Yes
5005076 Monthly Rollup Yes
5005106 Security Only Yes
5005090 Monthly Rollup Yes
5005095 Security Only Yes
5005099 Monthly Rollup Yes
5005094 Security Only Yes

Known Exploits

Acknowledgments