cbcvebase.
CVE-2020-1048
published 2020-05-21

CVE-2020-1048: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who…

PriorityP278high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
16.50%
96.8th percentile
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application. The update addresses the vulnerability by correcting how the Windows Print Spooler Component writes to the file system.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.10240.0 < publicationpublication
microsoftwindows_10_version_1607>= 10.0.14393.0 < publicationpublication
microsoftwindows_10_version_1709>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.17763.0 < publicationpublication
microsoftwindows_10_version_1903_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_arm64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_x64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1909>= 10.0.0 < publicationpublication
microsoftwindows_7>= 6.1.0 < publicationpublication
microsoftwindows_7_service_pack_1>= 6.1.0 < publicationpublication
microsoftwindows_8.1>= 6.3.0 < publicationpublication
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < publicationpublication
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < publicationpublication
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < publicationpublication

Detection & IOCsextracted from sources · hover to see the quote

pathmodules/exploits/windows/local/cve_2020_1048_printerdemon.rb
processspoolsv.exe
  • CVE-2020-1048 (PrintDemon) abuses the Windows Print Spooler service to write an arbitrary DLL to the filesystem; monitor for unexpected DLL files being written by spoolsv.exe to non-standard paths, as the DLL cannot be removed once loaded by the service.
  • CVE-2020-1337 is a patch bypass for CVE-2020-1048; detections for CVE-2020-1048 Print Spooler arbitrary file write should also be evaluated against CVE-2020-1337 exploitation attempts.
  • ·The Metasploit module for CVE-2020-1048 (PrinterDemon) installs a persistent elevated DLL backdoor that cannot be removed once loaded, because the Print Spooler service restarts automatically; incident responders should be aware that remediation requires more than simply stopping the service.
  • ·CVE-2020-1048 was patched in May 2020, but the patch was found to be incomplete; CVE-2020-1337 represents a bypass of that patch and was disclosed at Black Hat 2020.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.