Vulnerability record · CVE-2021-34481 · published 16 July 2021
CVE-2021-34481: Windows Print Spooler privileged file operation RCE
Microsoft · Windows 10
The Windows Print Spooler service improperly performs privileged file operations, allowing an attacker to execute arbitrary code as SYSTEM. It affects a broad set of Windows client and server versions, and Microsoft released fixes in August 2021 that also change Point and Print default behavior.
Description
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and SYSTEM-level code execution, plus a very high EPSS percentile, outweigh the absence of KEV listing.
What it is
The Windows Print Spooler service improperly performs privileged file operations, allowing an attacker to execute arbitrary code as SYSTEM. It affects a broad set of Windows client and server versions, and Microsoft released fixes in August 2021 that also change Point and Print default behavior.
Impact
An attacker gains arbitrary code execution with SYSTEM privileges, enabling program installation, data modification or deletion, and creation of accounts with full user rights.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L) on the target.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is high at 0.477 (98.8th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Microsoft security updates referenced in the MSRC advisory for CVE-2021-34481 immediately.
- Review and apply the Point and Print default behavior changes described in KB5005652.
- Restrict or disable the Print Spooler service on systems that do not require printing.
- Limit and audit low-privileged accounts that can reach print services on servers and workstations.
Detection
- Monitor for unexpected child processes spawned by spoolsv.exe, especially SYSTEM-level shells or scripting hosts.
- Alert on suspicious file writes or privilege-related operations originating from the Print Spooler service.
- Audit print spooler service status and Point and Print registry settings across the estate for drift from hardened baselines.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-34481 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34481), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.