CVE-2021-1675KEV · OVERDUE

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

High · published June 9, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.8. It is confirmed in active exploitation. It sits in the 99.7th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.8
EPSS
86%
Percentile
99.7
In the wild
Confirmed
What it is

🚨 A dangerous flaw lurks in the Windows Print Spooler service that lets attackers execute code remotely—imagine leaving your front door wide open for any intruder! 🔥 Think of the Windows Print Spooler as a busy restaurant kitchen, where orders pile up. If someone sneaks in and switches out the order tickets, they could serve anything—maybe a dish seasoned with malicious code instead of the intended meal! This vulnerability could allow an attacker to take full control over the affected system, stealing sensitive data, deploying malware, or even pivoting to other systems on your network. With the right access, they could cause absolute chaos—think of it as a kitchen staff turning rogue and poisoning the entire dinner service!

Put simply

Think of the Windows Print Spooler as a busy restaurant kitchen, where orders pile up. If someone sneaks in and switches out the order tickets, they could serve anything—maybe a dish seasoned with malicious code instead of the intended meal! The flaw in Windows Print Spooler allows for remote code execution (RCE), where an attacker can send specially crafted print jobs that the service executes, thus gaining control over the affected machine.

What to do

This vulnerability could allow an attacker to take full control over the affected system, stealing sensitive data, deploying malware, or even pivoting to other systems on your network. With the right access, they could cause absolute chaos—think of it as a kitchen staff turning rogue and poisoning the entire dinner service! To protect against this vulnerability, apply the latest security patches from Microsoft immediately. It’s also wise to disable the Print Spooler service if it’s not needed or restrict its use to trusted users and devices. Keep an eye on your network for any suspicious activity! You’ve got this! By following these steps, you’ll lock down your systems and keep the bad guys at bay. 🛡️

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.86132 · 99.7th percentile
Published
2021-06-09T03:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (17)
ProductVersionsFixed in
microsoft/windows_10_1507< 10.0.10240.1896710.0.10240.18967
microsoft/windows_10_1607< 10.0.14393.446710.0.14393.4467
microsoft/windows_10_1809< 10.0.17763.199910.0.17763.1999
microsoft/windows_10_1909< 10.0.18363.162110.0.18363.1621
microsoft/windows_10_2004< 10.0.19041.105210.0.19041.1052
microsoft/windows_10_20h2< 10.0.19042.105210.0.19042.1052
microsoft/windows_10_21h1< 10.0.19043.105210.0.19043.1052
microsoft/windows_7all versions
microsoft/windows_8.1all versions
microsoft/windows_rt_8.1all versions
microsoft/windows_server_2004< 10.0.19041.105210.0.19041.1052
microsoft/windows_server_2008all versions
microsoft/windows_server_2008all versions
microsoft/windows_server_2012all versions
microsoft/windows_server_2012all versions
microsoft/windows_server_2016< 10.0.14393.446710.0.14393.4467
microsoft/windows_server_2019< 10.0.17763.199910.0.17763.1999
References (11)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 08 JUN 22:46Z
    Windows Print Spooler Remote Code Execution Vulnerability
    cvelistv5