Skip to main content

CVE detail

CVE-2021-36958

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

CVSS 7.8 · HighBuzz score 46.4

Buzz score

Why this CVE is surfacing

Buzz score total 46.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 26.4 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
26.4
13 evidence mentions in the snapshot
Diversity score
20.0
8 sources across 4 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
13 source links · newest first
  • Windows 11 2022 (22H2 release) is now out, and Microsoft has once again placed a heavy emphasis on security. The good news for this release is that even Windows Home versions can receive some of the key security features with no additional Windows or Microsoft 365 licensing. Review the Windows 11 22H2 security baseline documents […]

    newswww.csoonline.comSep 27, 2022, 9:00 AM
  • Prodaft security researchers exploited a vulnerability in the recovery servers used by the Conti Ransomware-as-a-Service (RaaS), which allowed them to gain insight into the inner workings of the ransomware.

    newswww.securityweek.comNov 22, 2021, 3:55 PM
  • 20th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 20th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has seen a global surge in the black market for fake COVID-19 vaccine certificates on Telegram, following US President Biden’s vaccine mandate announcements. The black market has expanded to […]

    vendorresearch.checkpoint.comSep 19, 2021, 3:08 PM
  • 16th August – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 16th August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has revealed that the threat actor behinds last month’s cyber-attack on Iran’s train system is “Indra”, a group that identifies itself as Iranian regime opposition. They used similar tools […]

    vendorresearch.checkpoint.comAug 16, 2021, 5:25 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Microsoft confirms another Windows Print Spooler bug, offers workaround (CVE-2021-36958) A day after the August 2021 Patch Tuesday, Microsoft has released an out-of-band security advisory acknowledging the existence of yet another Print Spooler vulnerability (CVE-2021-36958). World Health Organization CISO suggests a holistic approach to cybersecurity In this interview with Help Net Security, Flavio Aggio, CISO at the World Health Organization, talks … More →

    newswww.helpnetsecurity.comAug 15, 2021, 8:00 AM
  • Another ransomware gang, the Vice Society ransomware operators, is using Windows print spooler PrintNightmare exploits in its attacks. The Vice Society ransomware operators are actively exploiting Windows print spooler PrintNightmare vulnerability in their attacks against Windows servers. The PrintNightmare flaws (tracked as (CVE-2021-1675, CVE-2021-34527, and CVE-2021-36958) reside in the Windows Print Spooler service, print drivers, and the Windows Point and […]

    newssecurityaffairs.comAug 13, 2021, 5:16 PM
  • A day after the August 2021 Patch Tuesday, Microsoft has released an out-of-band security advisory acknowledging the existence of yet another Print Spooler vulnerability (CVE-2021-36958). Its discovery has been attributed to Victor Mata of FusionX, Accenture Security, who says he reported it in December 2020, but the flaw was also publicly disclosed mid-July 2021 by researcher Benjamin Delpy, along with a PoC. About CVE-2021-36958 Microsoft says that CVE-2021-36958 is a remote code execution vulnerability exists … More →

    newswww.helpnetsecurity.comAug 13, 2021, 9:15 AM
  • https://www.kb.cert.org/vuls/id/131152www.kb.cert.org

    No excerpt available.

    Exploitwww.kb.cert.orgAug 12, 2021, 6:15 PM
  • No excerpt available.

    Vendor Advisoryportal.msrc.microsoft.comAug 12, 2021, 6:15 PM
  • No excerpt available.

    Vendor Advisorymsrc.microsoft.comAug 12, 2021, 6:15 PM
  • Threat actors behind the Magniber Ransomware are using PrintNightmare exploits in attacks aimed at Windows servers. Threat actors behind the Magniber Ransomware are exploiting the PrintNightmare flaws (CVE-2021-1675, CVE-2021-34527, and CVE-2021-36958) to infect Windows servers. The PrintNightmare flaws reside in the Windows Print Spooler service, print drivers, and the Windows Point and Print feature. A few hours ago […]

    newssecurityaffairs.comAug 12, 2021, 4:01 PM
  • Exasperated Windows fleet administrators woke up Thursday to news of a new, unpatched Print Spooler vulnerability that leaves machines exposed to remote code execution attacks.

    newswww.securityweek.comAug 12, 2021, 3:53 PM
  • Microsoft is warning of another zero-day Windows print spooler vulnerability, tracked as CVE-2021-36958, that could allow local attackers to gain SYSTEM privileges. Microsoft published a security advisory to warn its customers of another remote code execution zero-vulnerability, tracked as CVE-2021-36958, that resides in the Windows Print Spooler component. A local attacker could exploit the vulnerability […]

    newssecurityaffairs.comAug 12, 2021, 7:52 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence