CVE-2020-1337Time-of-check Time-of-use (TOCTOU) Race Condition in Microsoft Windows 10 Version 1507

Severity
7.8HIGHNVD
EPSS
55.3%
top 1.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 24

Description

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or a

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages24 packages

CVEListV5microsoft/windows_7_service_pack_16.1.0publication

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9mv8-62q2-x7p7: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Win2022-05-24
CVEList
Windows Print Spooler Elevation of Privilege Vulnerability2020-08-17

💥Exploits & PoCs

2
Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution2021-04-08
Exploit-DB
Online-Exam-System 2015 - 'feedback' SQL Injection2020-06-05

🔍Detection Rules

3
Elastic
Deprecated - Suspicious PrintSpooler Service Executable File Creation
YARA
HKTL_NET_GUID_CVE_2020_1337
Elastic
Suspicious Print Spooler SPL File Created

📋Vendor Advisories

1
Microsoft
Windows Print Spooler Elevation of Privilege Vulnerability2020-08-11
CVE-2020-1337 — Microsoft vulnerability | cvebase