cbcvebase.
CVE-2020-1048
published 2020-05-21

CVE-2020-1048: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows…

PriorityP277high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
16.50%
96.6th percentile
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.

Affected

70 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1903_for_32-bit_systems

Detection & IOCsextracted from sources · hover to see the quote

pathmodules/exploits/windows/local/cve_2020_1048_printerdemon.rb
processspoolsv.exe
  • CVE-2020-1048 (PrintDemon) abuses the Windows Print Spooler service to write an arbitrary DLL to the filesystem; monitor for unexpected DLL files being written by spoolsv.exe to non-standard paths, as the DLL cannot be removed once loaded by the service.
  • CVE-2020-1337 is a patch bypass for CVE-2020-1048; detections for CVE-2020-1048 Print Spooler arbitrary file write should also be evaluated against CVE-2020-1337 exploitation attempts.
  • ·The Metasploit module for CVE-2020-1048 (PrinterDemon) installs a persistent elevated DLL backdoor that cannot be removed once loaded, because the Print Spooler service restarts automatically; incident responders should be aware that remediation requires more than simply stopping the service.
  • ·CVE-2020-1048 was patched in May 2020, but the patch was found to be incomplete; CVE-2020-1337 represents a bypass of that patch and was disclosed at Black Hat 2020.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.