CVE-2020-1048: Windows Print Spooler Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
Other sources
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application. The update addresses the vulnerability by correcting how the Windows Print Spooler Component writes to the file system.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556843 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556852 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556854 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556846 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
What is CVE-2020-1048?
CVE-2020-1048 is an elevation of privilege vulnerability in the Windows Print Spooler service that allows arbitrary writing to the file system.
What is the severity of CVE-2020-1048?
The severity of CVE-2020-1048 is high, with a severity rating of 7.8 out of 10.
Which software is affected by CVE-2020-1048?
The following software versions are affected by CVE-2020-1048: Microsoft Windows 10 (all versions), Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows Server 2008 SP2, Windows Server 2008 R2 SP1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016 (all versions), and Windows Server 2019.
How can I fix CVE-2020-1048?
To fix CVE-2020-1048, apply the security updates provided by Microsoft as mentioned in the advisory.
Where can I find more information about CVE-2020-1048?
You can find more information about CVE-2020-1048 in the following references: [Link 1](http://packetstormsecurity.com/files/158222/Windows-Print-Spooler-Privilege-Escalation.html), [Link 2](http://packetstormsecurity.com/files/159217/Microsoft-Spooler-Local-Privilege-Elevation.html), [Link 3](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1048).