CVE-2021-36936
vulnerability analysis and mitigation

Overview

Windows Print Spooler Remote Code Execution Vulnerability (CVE-2021-36936) was disclosed in August 2021 as part of Microsoft's ongoing investigation into Print Spooler vulnerabilities. This vulnerability affects Windows Print Spooler service, which is enabled by default on domain controllers, desktops, and servers (Arctic Wolf).

Technical details

The vulnerability has received a CVSS v3.1 base score of 9.8 (CRITICAL) from NIST with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, while Microsoft assigned it a slightly lower score of 8.8 (HIGH) with a vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

As a Remote Code Execution (RCE) vulnerability, successful exploitation could allow attackers to execute unauthorized code on affected systems with elevated privileges. The vulnerability affects multiple versions of Windows, including Windows 10, Windows 7 SP1, and Windows 8.1 (NVD).

Mitigation and workarounds

Microsoft released security patches for this vulnerability as part of their August 2021 Patch Tuesday updates. It is strongly recommended to apply these patches as soon as possible to protect against potential exploitation (Arctic Wolf).

Community reactions

This vulnerability was part of a series of Print Spooler vulnerabilities that Microsoft had been addressing since June 2021, including the notorious PrintNightmare vulnerability. The discovery of CVE-2021-36936 demonstrated Microsoft's continued efforts to identify and patch security issues in the Print Spooler service (Krebs on Security).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management