CVE-2021-1640: Microsoft Windows Print Spooler Time-Of-Check Time-Of-Use Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Print Spooler service. By creating a directory junction, an attacker can abuse the Print Spooler service to delete a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
Windows Print Spooler Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23298Patch KB5000840 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.19968Patch KB5000853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.24566Patch KB5000851 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.19968Patch KB5000848 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.21070Patch KB5000856 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.4283Patch KB5000803 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.18874Patch KB5000807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.867Patch KB5000802 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.18363.1440Patch KB5000808 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.1817Patch KB5000822 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17134.2087Patch KB5000809
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1640?
CVE-2021-1640 has a severity rating of important according to Microsoft, indicating a potential denial-of-service vulnerability.
How do I fix CVE-2021-1640?
To fix CVE-2021-1640, install the relevant security updates provided by Microsoft for your affected version of Windows.
What versions of Windows are affected by CVE-2021-1640?
CVE-2021-1640 affects various versions of Microsoft Windows, including Windows 10, Windows Server, and Windows 7.
Can CVE-2021-1640 be exploited remotely?
No, CVE-2021-1640 requires local access for exploitation, as the attacker must execute low-privileged code on the target system.
What is the impact of CVE-2021-1640 on my system?
CVE-2021-1640 can lead to a denial-of-service condition, potentially making the system unresponsive.