Windows Print Spooler Remote Code Execution Vulnerability
Summary
| CVE | CVE-2021-36958 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-12 18:15:10 UTC |
| Updated | 2026-08-10 16:18:03 UTC |
| Description | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.305720000 probability, percentile 0.980670000 (date 2026-08-11)
Problem Types: NVD-CWE-noinfo | Remote Code Execution
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C |
| 2.0 | [email protected] | Primary | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Microsoft | Windows 10 Version 1507 | affected 10.0.10240.0 10.0.10240.19060 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 1607 | affected 10.0.14393.0 10.0.14393.4651 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 1809 | affected 10.0.17763.0 10.0.17763.2183 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 1809 | affected 10.0.0 10.0.17763.2183 custom | ARM64-based Systems |
| CNA | Microsoft | Windows 10 Version 1909 | affected 10.0.0 10.0.18363.1801 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 2004 | affected 10.0.0 10.0.19041.1237 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 10 Version 20H2 | affected 10.0.0 10.0.19042.1237 custom | 32-bit Systems, ARM64-based Systems |
| CNA | Microsoft | Windows 10 Version 21H1 | affected 10.0.0 10.0.19043.1237 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows 7 | affected 6.1.0 6.1.7601.25712 custom | 32-bit Systems |
| CNA | Microsoft | Windows 7 Service Pack 1 | affected 6.1.0 6.1.7601.25712 custom | x64-based Systems |
| CNA | Microsoft | Windows 8.1 | affected 6.3.0 6.3.9600.20120 custom | 32-bit Systems, ARM64-based Systems, x64-based Systems |
| CNA | Microsoft | Windows Server 2008 R2 Service Pack 1 | affected 6.1.7601.0 6.1.7601.25712 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2008 R2 Service Pack 1 Server Core Installation | affected 6.1.7601.0 6.1.7601.25712 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2008 Service Pack 2 | affected 6.0.6003.0 6.0.6003.21218 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows Server 2008 Service Pack 2 Server Core Installation | affected 6.0.6003.0 6.0.6003.21218 custom | 32-bit Systems, x64-based Systems |
| CNA | Microsoft | Windows Server 2012 | affected 6.2.9200.0 6.2.9200.23462 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2012 Server Core Installation | affected 6.2.9200.0 6.2.9200.23462 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2012 R2 | affected 6.3.9600.0 6.3.9600.20120 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2012 R2 Server Core Installation | affected 6.3.9600.0 6.3.9600.20120 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2016 | affected 10.0.14393.0 10.0.14393.4651 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2016 Server Core Installation | affected 10.0.14393.0 10.0.14393.4651 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2019 | affected 10.0.17763.0 10.0.17763.2183 custom | x64-based Systems |
| CNA | Microsoft | Windows Server 2019 Server Core Installation | affected 10.0.17763.0 10.0.17763.2183 custom | x64-based Systems |
| CNA | Microsoft | Windows Server Version 2004 | affected 10.0.0 10.0.19041.1237 custom | x64-based Systems |
| CNA | Microsoft | Windows Server Version 20H2 | affected 10.0.0 10.0.19042.1237 custom | x64-based Systems |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.kb.cert.org/vuls/id/131152 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | |
| Security Update Guide - Microsoft Security Response Center | af854a3a-2127-422b-91ae-364da2661108 | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36958 | [email protected] | msrc.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.