CVE-2020-1048

HIGH EXPLOITED

Microsoft Spooler Local Privilege Elevation Vulnerability

Title source: metasploit

Description

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.

Exploits (7)

nomisec WORKING POC 13 stars
by shubham0d · local
https://github.com/shubham0d/CVE-2020-1048
nomisec WRITEUP 3 stars
by zveriu · poc
https://github.com/zveriu/CVE-2009-0229-PoC
nomisec WORKING POC 2 stars
by Ken-Abruzzi · local
https://github.com/Ken-Abruzzi/CVE-2020-1048
nomisec WORKING POC 1 stars
by talsim · local
https://github.com/talsim/printDemon2system
nomisec WORKING POC
by Y3A · local
https://github.com/Y3A/cve-2020-1048
metasploit WORKING POC NORMAL
by Yarden Shafir, Alex Ionescu, shubham0d, bwatters-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2020_1048_printerdemon.rb
patchapalooza WORKING POC
by neofito · local
https://github.com/neofito/CVE-2020-1337

Scores

CVSS v3 7.8
EPSS 0.7396
EPSS Percentile 98.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-08-20
CWE
CWE-669
Status published
Products (19)
microsoft/windows_10
microsoft/windows_10 1607
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_10 1909
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 9 more
Published May 21, 2020
Tracked Since Feb 18, 2026