Windows Print Spooler Remote Code Execution Vulnerability
Summary
| CVE | CVE-2021-34481 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-16 21:15:10 UTC |
| Updated | 2026-08-10 16:17:49 UTC |
| Description | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.474370000 probability, percentile 0.987300000 (date 2026-08-11)
Problem Types: CWE-269 | Remote Code Execution
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 10 | - | All | All | All |
| Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1809 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1909 | All | All | All |
| Operating System | Microsoft | Windows 10 | 2004 | All | All | All |
| Operating System | Microsoft | Windows 10 | 20h2 | All | All | All |
| Operating System | Microsoft | Windows 10 | 21h1 | All | All | All |
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows 8.1 | - | All | All | All |
| Operating System | Microsoft | Windows Rt 8.1 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2012 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | 2004 | All | All | All |
| Operating System | Microsoft | Windows Server 2019 | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Microsoft | Windows 10 Version 1507 | affected 10.0.10240.0 10.0.10240.19022 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 1607 | affected 10.0.14393.0 10.0.14393.4583 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 1809 | affected 10.0.17763.0 10.0.17763.2114 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 1809 | affected 10.0.0 10.0.17763.2114 custom | ARM64-based Systems |
| CNA | Microsoft | Windows 10 Version 1909 | affected 10.0.0 10.0.18363.1734 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 2004 | affected 10.0.0 10.0.19041.1165 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 20H2 | affected 10.0.0 10.0.19042.1165 custom | 32-bit Systems, ARM64-based Systems |
| CNA | Microsoft | Windows 10 Version 21H1 | affected 10.0.0 10.0.19043.1165 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 7 | affected 6.1.0 6.1.7601.25685 custom | 32-bit Systems |
| CNA | Microsoft | Windows 7 Service Pack 1 | affected 6.1.0 6.1.7601.25685 custom | x64-based Systems |
| CNA | Microsoft | Windows 8.1 | affected 6.3.0 6.3.9600.20094 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows Server 2008 R2 Service Pack 1 | affected 6.1.7601.0 6.1.7601.25685 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2008 R2 Service Pack 1 Server Core Installation | affected 6.1.7601.0 6.1.7601.25685 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2008 Service Pack 2 | affected 6.0.6003.0 6.0.6003.21192 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows Server 2008 Service Pack 2 Server Core Installation | affected 6.0.6003.0 6.0.6003.21192 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows Server 2012 | affected 6.2.9200.0 6.2.9200.23435 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2012 Server Core Installation | affected 6.2.9200.0 6.2.9200.23435 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2012 R2 | affected 6.3.9600.0 6.3.9600.20094 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2012 R2 Server Core Installation | affected 6.3.9600.0 6.3.9600.20094 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2016 | affected 10.0.14393.0 10.0.14393.4583 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2016 Server Core Installation | affected 10.0.14393.0 10.0.14393.4583 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2019 | affected 10.0.17763.0 10.0.17763.2114 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2019 Server Core Installation | affected 10.0.17763.0 10.0.17763.2114 custom | x64-based Systems |
| CNA | Microsoft | Windows Server Version 2004 | affected 10.0.0 10.0.19041.1165 custom | x64-based Systems |
| CNA | Microsoft | Windows Server Version 20H2 | affected 10.0.0 10.0.19042.1165 custom | x64-based Systems |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Update Guide - Microsoft Security Response Center | af854a3a-2127-422b-91ae-364da2661108 | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34481 | [email protected] | msrc.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 91796 Windows Print Spooler Remote Code Execution Vulnerability