7.8highHigh
CVE-2021-36958
Microsoft Windows
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 7.8 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Assigned by
- secure@microsoft.com
Dates
- Published
- 2021-08-12
- Last modified
- 2026-08-10
- Sources
- NVD
Affected products
- Microsoft Windowsall versions
As listed in the NVD configuration data. Not a statement about your estate.