cve-2021-34527
HIGH CVSS 8.8 cisa_known_exploited
Description
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
Timeline
- Published
- 2021-11-03
- Last Modified
- 2021-11-03
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 8.8,
"datePublished": "2021-11-03",
"dateUpdated": "2021-11-03",
"description": "Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.",
"dueDate": "2022-05-03",
"id": "CVE-2021-34527",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Known",
"notes": "Reference CISA's ED 21-04 (https://www.cisa.gov/news-events/directives/ed-21-04-mitigate-windows-print-spooler-service-vulnerability) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-04. https://nvd.nist.gov/vuln/detail/CVE-2021-34527",
"product": "Windows",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "HIGH",
"source": "cisa_known_exploited",
"title": "Microsoft Windows Print Spooler Remote Code Execution Vulnerability",
"vendor": "Microsoft"
}
Enrichment data
Aggregated bundle (all enrichments)