Executive brief
The Microsoft Windows Print Spooler service contains a vulnerability that allows for remote code execution. This flaw, often associated with the 'PrintNightmare' vulnerability class, enables an attacker to execute arbitrary code with system privileges.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.18967
- Microsoft Windows 10 1607 up to (excluding) 10.0.14393.4467
- Microsoft Windows 10 1809 up to (excluding) 10.0.17763.1999
- Microsoft Windows 10 1909 up to (excluding) 10.0.18363.1621
- Microsoft Windows 10 2004 up to (excluding) 10.0.19041.1052
- Microsoft Windows 10 20H2 up to (excluding) 10.0.19042.1052
- Microsoft Windows 10 21H1 up to (excluding) 10.0.19043.1052
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2004 up to (excluding) 10.0.19041.1052
- Microsoft Windows Server 2008 SP2
- Microsoft Windows Server 2008 R2 SP1
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4467
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.1999
Timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed
- 2021-06-08: patched: Initial patch released by Microsoft (later updated)