KEV · Actively exploited
CVE-2021-34527
CRITICAL 8.8
KEV
Windows Print Spooler Remote Code Execution Vulnerability
EPSS
94.24%
exploit likely
percentile 99.9%
CISA Known Exploited Vulnerability
- Added to KEV
- 2021-11-03
- Remediation deadline
- 2022-05-03
- Required action
- Apply updates per vendor instructions.
- Ransomware
- Yes, known ransomware campaign
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Fixed in Windows Server 2022 (Server Core installation) 10.0.20348.230 Windows Server 2022 10.0.20348.230 Windows Server 2019 (Server Core installation) 10.0.17763.2029 Windows Server 2019 10.0.17763.2029 Windows Server 2016 (Server Core installation) 10.0.14393.4470 Windows Server 2016 10.0.14393.4470 Windows 11 22H2 · 2022-H2 10.0.22621.674 Windows 11 21H2 · 2021-H2 10.0.22000.318 Windows 10 22H2 · 2022-H2 10.0.19045.2251 Windows 10 21H2 · 2021-H2 10.0.19044.1415 Windows 10 20H2 · 2020-H2 10.0.19042.1083 Windows 10 1809 · 2018-09 10.0.17763.2029 Windows 10 1607 · 2016-07 10.0.14393.4470