diff --git "a/202002503_\353\260\260\354\244\200\354\204\234_V0xe1/CVE-2021-34481 \354\206\214\352\260\234" "b/202002503_\353\260\260\354\244\200\354\204\234_V0xe1/CVE-2021-34481 \354\206\214\352\260\234" new file mode 100644 index 0000000..6f5cc7c --- /dev/null +++ "b/202002503_\353\260\260\354\244\200\354\204\234_V0xe1/CVE-2021-34481 \354\206\214\352\260\234" @@ -0,0 +1,16 @@ +분석 대상 : CVE-2021-34481 +릴리스 날짜 : 2021.07.15 + +설명 : Windows Print Spooler Elevation of Privilege Vulnerability + +An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. +An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. +An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. + +An attacker must have the ability to execute code on a victim system to exploit this vulnerability. + +The workaround for this vulnerability is stopping and disabling the Print Spooler service. + + +Windows의 Print Spooler서비스가 권한이 존재하는 파일 작업을 부적절하게 수행할 때, 권한상승 취약점이 존재합니다. +성공적으로 이를 악용하면 SYSTEM권한으로 임의의 공격용 코드를 실행할 수 도 있습니다.