CVE-2020-1337 is an elevation of privilege vulnerability in the Windows Print Spooler service. The vulnerability exists because the Print Spooler improperly allows arbitrary writing to the file system, enabling attackers to exploit a flaw in the way the service handles file permissions and directory junctions. This issue is a bypass of the previous PrintDemon patch (CVE-2020-1048), allowing attackers to escalate privileges by writing files as SYSTEM. Exploitation requires local access and the ability to execute a specially crafted script or application, typically by a low-privileged user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2020-1337, a local privilege escalation vulnerability in the Microsoft Windows Print Spooler service. The exploit abuses a file write vulnerability to place a malicious DLL (ualapi.dll by default) in the system32 directory, which is then loaded by the Print Spooler service, granting SYSTEM privileges to the attacker. The module is highly configurable, allowing the user to specify custom paths and filenames, but defaults to targeting %WINDIR%\system32\ualapi.dll. The exploit is executed via a Meterpreter session and leverages PowerShell to run the attack script. The payload is a DLL generated by Metasploit, encoded in base64, and injected into the target system. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The main attack vector is local, requiring an existing session on the target machine. The module leaves artifacts on disk and may require a system reboot to complete the privilege escalation.
This repository is a proof-of-concept (POC) exploit for CVE-2020-1337, a Windows Print Spooler Elevation of Privilege vulnerability. The main code is in C++ and consists of a Visual Studio solution with two main source files: WerTrigger.cpp and TcpClient.cpp. WerTrigger.cpp orchestrates the exploit by creating a crafted Windows Error Reporting (WER) report file and directory, then triggers the Windows Error Reporting task to process it. After a short delay, it attempts to connect to a local TCP bind shell on 127.0.0.1:1337, which is expected to be spawned as a result of the exploit (typically by loading a malicious DLL). TcpClient.cpp implements the TCP client functionality for interacting with the shell. The exploit is local and targets vulnerable Windows systems. No external network endpoints are used; all actions are performed locally. The repository is structured as a Visual Studio C++ project and is intended for research and demonstration purposes.
This repository is a C# proof-of-concept exploit for CVE-2020-1337, a Windows Print Spooler vulnerability that allows local privilege escalation by planting a malicious DLL into the protected C:\Windows\System32 directory. The exploit leverages Windows printer APIs and NT object manager tricks (junctions and symlinks) to bypass protections and write an arbitrary file to System32. The main logic is in Program.cs, which orchestrates the attack in two steps: (1) initializing the printer and sending a crafted print job, and (2) after a manual reboot, creating a mount point and symlink to redirect the print spooler to write the attacker-supplied file into System32. The exploit requires local access and the ability to reboot the system. The codebase is structured as a Visual Studio C# project, with core logic in Program.cs, Printer.cs (printer API interactions), and Utils.cs (mount point and symlink creation). The attack targets Windows 7 and later, specifically exploiting the Print Spooler service. No network endpoints are involved; all actions are performed locally. The exploit is operational as a proof-of-concept and requires a user-supplied payload (DLL or binary) to be planted.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.