CVE-2020-1337

HIGH

Microsoft Windows 10 - TOCTOU Race Condition

Title source: rule

Description

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application. The update addresses the vulnerability by correcting how the Windows Print Spooler Component writes to the file system.

Exploits (6)

nomisec WORKING POC 171 stars
by sailay1996 · poc
https://github.com/sailay1996/cve-2020-1337-poc
nomisec WORKING POC 152 stars
by math1as · poc
https://github.com/math1as/CVE-2020-1337-exploit
nomisec WORKING POC 33 stars
by neofito · poc
https://github.com/neofito/CVE-2020-1337
nomisec WRITEUP 14 stars
by VoidSec · poc
https://github.com/VoidSec/CVE-2020-1337
metasploit WORKING POC EXCELLENT
by Peleg Hadar, Tomer Bar, 404death, sailay1996, bwatters-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2020_1337_printerdemon.rb

Scores

CVSS v3 7.8
EPSS 0.5542
EPSS Percentile 98.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-367
Status published

Affected Products (20)

microsoft/windows_10
microsoft/windows_10
microsoft/windows_10
microsoft/windows_10
microsoft/windows_10
microsoft/windows_10
microsoft/windows_10
microsoft/windows_10
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_2008
microsoft/windows_server_2008
microsoft/windows_server_2012
microsoft/windows_server_2012
... and 5 more

Timeline

Published Aug 17, 2020
Tracked Since Feb 18, 2026