Cyber Security

Microsoft Security Advisory – 2021 July 2nd

By Matsco Engineering Team

Microsoft Security Advisory – 2021 July 2nd

A zero-day remote code execution vulnerability in the Windows Print Spooler service (CVE-2021-34527) has been disclosed by security researchers. The vulnerability exists when the service improperly performs privileged file operation. The code that contains the vulnerability is in all versions of Windows, and Microsoft is still investigating if all versions are exploitable.

Successful exploitation of the vulnerability could give remote attackers full control of vulnerable systems, execute arbitrary code with elevated system privileges to install programs; view, change, or delete data; or create new accounts with full user rights.. To achieve RCE, attackers would need to target a user authenticated to the spooler service. Without authentication, the flaw could still be exploited to elevate privileges.

At this moment, Microsoft has not released a patch to fix this vulnerability. Microsoft recommend to disable to implement the workaround of disabling the Windows Print Spooler service or inbound remote printing through Group Policy.

For more information please see: Windows Print Spooler Remote Code Execution Vulnerability

Matsco Solutions are currently monitoring the update and will be reaching out to clients running the affected system to disable the print spooler services.

All resources

Get Started

Let's make technology work for you.

Get in touch about support, cloud, security, or a build-out, wherever in the world you operate.