CVE detail
CVE-2021-36958
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
Windows 11 2022 (22H2 release) is now out, and Microsoft has once again placed a heavy emphasis on security. The good news for this release is that even Windows Home versions can receive some of the key security features with no additional Windows or Microsoft 365 licensing. Review the Windows 11 22H2 security baseline documents […]
newswww.csoonline.comSep 27, 2022, 9:00 AM- Researchers Hack Conti Ransomware InfrastructureSecurityWeek
Prodaft security researchers exploited a vulnerability in the recovery servers used by the Conti Ransomware-as-a-Service (RaaS), which allowed them to gain insight into the inner workings of the ransomware.
newswww.securityweek.comNov 22, 2021, 3:55 PM - 20th September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has seen a global surge in the black market for fake COVID-19 vaccine certificates on Telegram, following US President Biden’s vaccine mandate announcements. The black market has expanded to […]
vendorresearch.checkpoint.comSep 19, 2021, 3:08 PM - 16th August – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 16th August, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has revealed that the threat actor behinds last month’s cyber-attack on Iran’s train system is “Indra”, a group that identifies itself as Iranian regime opposition. They used similar tools […]
vendorresearch.checkpoint.comAug 16, 2021, 5:25 PM Here’s an overview of some of last week’s most interesting news, articles and interviews: Microsoft confirms another Windows Print Spooler bug, offers workaround (CVE-2021-36958) A day after the August 2021 Patch Tuesday, Microsoft has released an out-of-band security advisory acknowledging the existence of yet another Print Spooler vulnerability (CVE-2021-36958). World Health Organization CISO suggests a holistic approach to cybersecurity In this interview with Help Net Security, Flavio Aggio, CISO at the World Health Organization, talks … More →
newswww.helpnetsecurity.comAug 15, 2021, 8:00 AMAnother ransomware gang, the Vice Society ransomware operators, is using Windows print spooler PrintNightmare exploits in its attacks. The Vice Society ransomware operators are actively exploiting Windows print spooler PrintNightmare vulnerability in their attacks against Windows servers. The PrintNightmare flaws (tracked as (CVE-2021-1675, CVE-2021-34527, and CVE-2021-36958) reside in the Windows Print Spooler service, print drivers, and the Windows Point and […]
newssecurityaffairs.comAug 13, 2021, 5:16 PM- Microsoft confirms another Windows Print Spooler bug, offers workaround (CVE-2021-36958)Help Net Security
A day after the August 2021 Patch Tuesday, Microsoft has released an out-of-band security advisory acknowledging the existence of yet another Print Spooler vulnerability (CVE-2021-36958). Its discovery has been attributed to Victor Mata of FusionX, Accenture Security, who says he reported it in December 2020, but the flaw was also publicly disclosed mid-July 2021 by researcher Benjamin Delpy, along with a PoC. About CVE-2021-36958 Microsoft says that CVE-2021-36958 is a remote code execution vulnerability exists … More →
newswww.helpnetsecurity.comAug 13, 2021, 9:15 AM - https://www.kb.cert.org/vuls/id/131152www.kb.cert.org
No excerpt available.
Exploitwww.kb.cert.orgAug 12, 2021, 6:15 PM - https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-36958portal.msrc.microsoft.com
No excerpt available.
Vendor Advisoryportal.msrc.microsoft.comAug 12, 2021, 6:15 PM - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36958msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comAug 12, 2021, 6:15 PM Threat actors behind the Magniber Ransomware are using PrintNightmare exploits in attacks aimed at Windows servers. Threat actors behind the Magniber Ransomware are exploiting the PrintNightmare flaws (CVE-2021-1675, CVE-2021-34527, and CVE-2021-36958) to infect Windows servers. The PrintNightmare flaws reside in the Windows Print Spooler service, print drivers, and the Windows Point and Print feature. A few hours ago […]
newssecurityaffairs.comAug 12, 2021, 4:01 PMExasperated Windows fleet administrators woke up Thursday to news of a new, unpatched Print Spooler vulnerability that leaves machines exposed to remote code execution attacks.
newswww.securityweek.comAug 12, 2021, 3:53 PMMicrosoft is warning of another zero-day Windows print spooler vulnerability, tracked as CVE-2021-36958, that could allow local attackers to gain SYSTEM privileges. Microsoft published a security advisory to warn its customers of another remote code execution zero-vulnerability, tracked as CVE-2021-36958, that resides in the Windows Print Spooler component. A local attacker could exploit the vulnerability […]
newssecurityaffairs.comAug 12, 2021, 7:52 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19171CVSS 9.6 · Critical
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium se…
- CVE-2026-19163CVSS 8.3 · High
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esc…
- CVE-2026-19158CVSS 7.5 · High
Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit…
- CVE-2026-19139CVSS 7.4 · High
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium se…
- CVE-2026-48399CVSS 7.5 · High
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this v…
- CVE-2026-48333CVSS 9.8 · Critical
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gai…