The bug first caught the attention of SafeBreach Labs researchers, Peleg Hadar and Tomer Bar.
Whereas, Yarden Shafir & Alex Ionescu have shared their own details about the bug in a blog post.
Briefly, a local privilege escalation vulnerability existed in this Windows component that remained “largely unchanged since Windows NT 4”.
The exploitation of thig bug in the wild is less likely since the bug cannot assist in remote attacks. However, for local attacks, the bug bears tremendous potential. Since it exists in the ‘Print’ service, something related to almost every app on a system, a potential attacker can easily exploit the vulnerability to gain elevated privileges (including admin) on the device.
In fact, Ionescu explained in a tweet that the bug can result in persistent impact despite patching.
https://twitter.com/aionescu/status/1260466215299973121
- aionescu
The SafeBreach Labs duo will present their findings in the upcoming BlackHat USA 2020. Yet, Ionescu has shared a PoC on GitHub.
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.Though, the users will receive the patches automatically with other updates.
Nonetheless, users may also manually update their systems to download the fixes quickly.
Let us know your thoughts in the comments.