Description
This exploit leverages a file write vulnerability in the print spooler service which will restart if stopped. Because the service cannot be stopped long enough to remove the dll, there is no way to remove the dll once it is loaded by the service. Essentially, on default settings, this module adds a permanent elevated backdoor.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/local/cve/2020_1048_printerdemonmsf undefined(2020_1048_printerdemon) > show actions ...actions...msf undefined(2020_1048_printerdemon) > set ACTION < action-name >msf undefined(2020_1048_printerdemon) > show options ...show and set options...msf undefined(2020_1048_printerdemon) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub