Kaspersky detailed Operation PowerFall, an attack chain that used the Windows elevation-of-privilege zero-day CVE-2020-0986 together with an Internet Explorer 11 remote code execution exploit to break out of the browser sandbox. The flaw was traced to the GDI Print/Print Spooler API, where attacker-controlled request data reached gdi32full.dll’s GdiPrinterThunk handler for INDEX_DocumentEvent and enabled an arbitrary pointer dereference. By abusing that path, attackers manipulated memory in splwow64.exe, turning browser compromise into code execution in a medium-integrity process.
The exploit reconstructed an encoded function pointer and overwrote fpDocumentEvent with an encoded LoadLibraryA pointer, then triggered library loading to execute attacker code. Microsoft’s pointer-encoding mechanism, documented through the Windows EncodePointer API, was part of the exploitation chain because the attackers had to recover and reuse encoded values correctly. Kaspersky said the bug closely resembled the earlier in-the-wild zero-day CVE-2019-0880, describing both as variants in the same vulnerable code path, while Microsoft’s fix tightened printer command validation and handle lookup logic in splwow64.exe to make OutputBuf-based exploitation far more difficult.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Securelist says Operation PowerFall was disclosed in August 2020 as a targeted attack that used two zero-days: an Internet Explorer 11 remote code execution exploit and the Windows elevation-of-privilege flaw CVE-2020-0986.
Securelist states that CVE-2019-0880, a related GdiPrinterThunk vulnerability in the handler for INDEX 118, had previously been exploited in the wild as a zero-day.
Microsoft patched CVE-2020-0986 and changed printer command validation and handle lookup logic in splwow64.exe, including requiring a valid driver ID and using FindDriverForCookie to securely retrieve the handle table. The changes were intended to make OutputBuf-based exploitation significantly harder and mitigate this broader bug class.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.