CVE-2020-1048
published 2020-05-21CVE-2020-1048: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows…
PriorityP277high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
16.50%
96.6th percentile
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1903_for_32-bit_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-1048 (PrintDemon) abuses the Windows Print Spooler service to write an arbitrary DLL to the filesystem; monitor for unexpected DLL files being written by spoolsv.exe to non-standard paths, as the DLL cannot be removed once loaded by the service. ↗
- →CVE-2020-1337 is a patch bypass for CVE-2020-1048; detections for CVE-2020-1048 Print Spooler arbitrary file write should also be evaluated against CVE-2020-1337 exploitation attempts. ↗
- ·The Metasploit module for CVE-2020-1048 (PrinterDemon) installs a persistent elevated DLL backdoor that cannot be removed once loaded, because the Print Spooler service restarts automatically; incident responders should be aware that remediation requires more than simply stopping the service. ↗
- ·CVE-2020-1048 was patched in May 2020, but the patch was found to be incomplete; CVE-2020-1337 represents a bypass of that patch and was disclosed at Black Hat 2020. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mvfv-8xhv-cj53: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Win
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1048 [HIGH] CWE-269 GHSA-mvfv-8xhv-cj53: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Win
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
GHSA
GHSA-fhv8-3g95-wgrc: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Win
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1070 [HIGH] CWE-269 GHSA-fhv8-3g95-wgrc: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Win
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1048.
VulnCheck
Microsoft Windows Incorrect Resource Transfer Between Spheres
vulncheck·2020·CVSS 7.8
CVE-2020-1048 [HIGH] Microsoft Windows Incorrect Resource Transfer Between Spheres
Microsoft Windows Incorrect Resource Transfer Between Spheres
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://attackerkb.com/topics/QoQvwrIqEV/cve-2020-1048-windows-print-spooler-elevation-of-privilege-vulnerability
Exploit PoC: https://vulncheck.com/xdb/547b9e8de953; https://vulncheck.com/xdb/4ed4a1f4d9ac; https://vulncheck.com/xdb/88397a5d8898; https://vulncheck.com/xdb/5
Microsoft
Windows Print Spooler Elevation of Privilege Vulnerability
vendor_msrc·2020-05-12·CVSS 7.8
CVE-2020-1048 [HIGH] Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application.
The update addresses the vulnerability by correcting how the Windows Print Spooler Component writes to the file system.
Microsoft Windows: Microsoft Windows
Issuing CNA: Microsoft
Impact: Elevation of Privilege
Elastic
Deprecated - Suspicious PrintSpooler Service Executable File Creation
elastic_rules·CVSS 7.8
CVE-2020-1048 [HIGH] Deprecated - Suspicious PrintSpooler Service Executable File Creation
Deprecated - Suspicious PrintSpooler Service Executable File Creation
Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service. For more
information refer to the following CVE's - CVE-2020-1048, CVE-2020-1337 and CVE-2020-1300 and verify that the impacted
system is patched.
Query:
event.category : "file" and host.os.type : "windows" and event.type : "creation" and
process.name : "spoolsv.exe" and file.extension : "dll"
Elastic
Suspicious Print Spooler SPL File Created
elastic_rules·CVSS 7.8
CVE-2020-1048 [HIGH] Suspicious Print Spooler SPL File Created
Suspicious Print Spooler SPL File Created
Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service including
CVE-2020-1048 and CVE-2020-1337.
Query:
file where host.os.type == "windows" and event.type != "deletion" and
file.extension : "spl" and
file.path : "?:\\Windows\\System32\\spool\\PRINTERS\\*" and
not process.name : ("spoolsv.exe",
"printfilterpipelinesvc.exe",
"PrintIsolationHost.exe",
"splwow64.exe",
"msiexec.exe",
"poqexec.exe",
"System") and
not user.id : "S-1-5-18" and
not process.executable :
("?:\\Windows\\System32\\mmc.exe",
"\\Device\\Mup\\*.exe",
"?:\\Windows\\System32\\svchost.exe",
"?:\\Windows\\System32\\mmc.exe",
"?:\\Windows\\System32\\printui.exe",
"?:\\Windows\\System32\\mstsc.exe",
"?:\\Windows\\System32\\spool\\*.exe
Tenable
CVE-2021-1675: Proof-of-Concept Leaked for Critical Windows Print Spooler Vulnerability
blogs_tenable·2021-06-29·CVSS 7.8
[HIGH] CVE-2021-1675: Proof-of-Concept Leaked for Critical Windows Print Spooler Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, August 2020 Edition
blogs_krebs·2020-08-11·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, August 2020 Edition
Microsoft today released updates to plug at least 120 security holes in its Windows operating systems and supported software, including two newly discovered vulnerabilities that are actively being exploited. Yes, good people of the Windows world, it’s time once again to backup and patch up!
At least 17 of the bugs squashed in August’s patch batch address vulnerabilities Microsoft rates as “critical,” meaning they can be exploited by miscreants or malware to gain complete, remote control over an affected system with little or no help from users. This is the sixth month in a row Microsoft has shipped fixes for more than 100 flaws in its products.
The most concerning of these appears to be CVE-2020-1380 , which is a weaknesses in Internet Explorer that could result in system compromise just
Tenable
Microsoft’s August 2020 Patch Tuesday Addresses 120 CVEs (CVE-2020-1337)
blogs_tenable·2020-08-11·CVSS 7.8
[HIGH] Microsoft’s August 2020 Patch Tuesday Addresses 120 CVEs (CVE-2020-1337)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, August 2020 Edition
blogs_krebs·2020-08-11·CVSS 7.8
CVE-2020-1380 [HIGH] Microsoft Patch Tuesday, August 2020 Edition
Microsoft today released updates to plug at least 120 security holes in its Windows operating systems and supported software, including two newly discovered vulnerabilities that are actively being exploited. Yes, good people of the Windows world, it’s time once again to backup and patch up!
The most concerning of these appears to be CVE-2020-1380, which is a weaknesses in Internet Explorer that could result in system compromise just by browsing with IE to a hacked or malicious website. Microsoft’s advisory says this flaw is currently being exploited in active attacks.
The other flaw enjoying active exploitation is CVE-2020-1464, which is a “spoofing” bug in virtually all supported versions of Windows that allows an attacker to bypass Windows security features and load improperly signed f
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901 , a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provi
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
CVE-2020-0901 [CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901, a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the full Snort rule
Crowdstrike
Security Advisory: MSRPC Printer Spooler Relay (CVE-2021-1678)
blogs_crowdstrike·CVSS 8.8
CVE-2026-20929 [HIGH] Security Advisory: MSRPC Printer Spooler Relay (CVE-2021-1678)
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
Magniber Ransomware Caught Using PrintNightmare Vulnerability
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Magniber Ransomware Caught Using PrintNightmare Vulnerability
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
Security Advisory: MSRPC Printer Spooler Relay (CVE-2021-1678)
blogs_crowdstrike·CVSS 8.8
CVE-2026-20929 [HIGH] Security Advisory: MSRPC Printer Spooler Relay (CVE-2021-1678)
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
Magniber Ransomware Caught Using PrintNightmare Vulnerability
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Magniber Ransomware Caught Using PrintNightmare Vulnerability
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Bugzilla
CVE-2020-6106 f2fs-tools: specially crafted filesystem can be used to disclose information
bugzilla·2020-10-15·CVSS 5.5
CVE-2020-6106 [MEDIUM] CVE-2020-6106 f2fs-tools: specially crafted filesystem can be used to disclose information
CVE-2020-6106 f2fs-tools: specially crafted filesystem can be used to disclose information
An exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13. A specially crafted filesystem can be used to disclose information. An attacker can provide a malicious file to trigger this vulnerability.
Reference:
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1048
Discussion:
Created f2fs-tools tracking bugs for this issue:
Affects: epel-7 [bug 1888778]
Affects: fedora-all [bug 1888777]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual comm
http://packetstormsecurity.com/files/158222/Windows-Print-Spooler-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/159217/Microsoft-Spooler-Local-Privilege-Elevation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1048http://packetstormsecurity.com/files/158222/Windows-Print-Spooler-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/159217/Microsoft-Spooler-Local-Privilege-Elevation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1048
2020-05-21
Published
Exploited in the wild