Incorrect permission assignment for critical resource in Microsoft Windows and Windows Server - CVE-2021-36958
Published: August 11, 2021 / Updated: August 12, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists in Windows Print Spooler service due to improperly performed privileged file operations. A local user can send a specially crafted request to the Print Spooler service and execute arbitrary code with SYSTEM privileges.
Affected software
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
VASA Provider Standalone
How to mitigate CVE-2021-36958
Solutions Enabler - addressed in versions 9.1.0.18, 9.2.3.0
Unisphere 360 - addressed in versions 9.1.0.29, 9.2.3.3
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.31, 9.2.3.4
Unisphere for PowerMax - addressed in versions 9.1.0.31, 9.2.3.4
VASA Provider Standalone - addressed in versions 9.1.0.723, 9.2.3.0