#VU55790 Incorrect permission assignment for critical resource in Windows and Windows Server - CVE-2021-36958

 

#VU55790 Incorrect permission assignment for critical resource in Windows and Windows Server - CVE-2021-36958

Published: August 11, 2021 / Updated: August 12, 2021


Vulnerability identifier: #VU55790
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2021-36958
CWE-ID: CWE-732
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Windows
Windows Server
Software vendor:
Microsoft

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists in Windows Print Spooler service due to improperly performed privileged file operations. A local user can send a specially crafted request to the Print Spooler service and execute arbitrary code with SYSTEM privileges.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links