IM
IronMonkey Threat Research

CVE-2021-1675 HIGH

Published: 2021-06-08 | Last Modified: 2025-10-30 | Status: Analyzed

Description

Windows Print Spooler Remote Code Execution Vulnerability

Additional Descriptions (1)

Una vulnerabilidad de Escalada de Privilegios de Windows Print Spooler

CVSS Metrics

Base Score: 7.8 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 1.8

Impact Score: 5.9

Base Score: 9.3 (HIGH)

AV:N/AC:M/Au:N/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-Other

Affected Products

Vendor Product Version Update Type
microsoft windows_10_1507 * <built-in method update of dict object at 0x7e60a8896980> Operating System
microsoft windows_10_1607 * <built-in method update of dict object at 0x7e60a8894300> Operating System
microsoft windows_10_1809 * <built-in method update of dict object at 0x7e60bafae840> Operating System
microsoft windows_10_1909 * <built-in method update of dict object at 0x7e60bafaffc0> Operating System
microsoft windows_10_2004 * <built-in method update of dict object at 0x7e60a8895080> Operating System
microsoft windows_10_20h2 * <built-in method update of dict object at 0x7e60a8894280> Operating System
microsoft windows_10_21h1 * <built-in method update of dict object at 0x7e60bafadb00> Operating System
microsoft windows_7 - <built-in method update of dict object at 0x7e60bafaf500> Operating System
microsoft windows_8.1 - <built-in method update of dict object at 0x7e60a88969c0> Operating System
microsoft windows_rt_8.1 - <built-in method update of dict object at 0x7e60a88944c0> Operating System
microsoft windows_server_2004 * <built-in method update of dict object at 0x7e60a8894d40> Operating System
microsoft windows_server_2008 - <built-in method update of dict object at 0x7e60e885ae80> Operating System
microsoft windows_server_2008 r2 <built-in method update of dict object at 0x7e60a8896b40> Operating System
microsoft windows_server_2012 - <built-in method update of dict object at 0x7e60bafae240> Operating System
microsoft windows_server_2012 r2 <built-in method update of dict object at 0x7e60bafaecc0> Operating System
microsoft windows_server_2016 * <built-in method update of dict object at 0x7e60bafafdc0> Operating System
microsoft windows_server_2019 * <built-in method update of dict object at 0x7e60e8858480> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_10_2004:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2004:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*

References

Notification
Message here