CVE-2010-2729: Input Validation
The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Affected Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 systems are exposed when printer sharing is enabled.
Does an attacker need credentials or local access?
No. The vulnerability is remotely reachable over RPC, and the supplied vector indicates that authentication is not required.
Has this vulnerability been used in real attacks?
Yes. The vulnerability was exploited in the wild in September 2010.