New Local Privilege Escalation Exploit Targets Windows Print Drivers

New Local Privilege Escalation Exploit Targets Windows Print Drivers

First seen 8 Sep 2026, 21:44 UTC Sploitus 61.5

Article Content

Browse articles
ThreatCluster

The 'concealed_position' exploit, revealed at DEF CON 29, allows low-privileged users to escalate privileges to SYSTEM on Windows by exploiting vulnerabilities in printer drivers. It utilizes four known CVEs: CVE-2021-35449, CVE-2021-38085, CVE-2019-19363, and CVE-2020-1300. The exploit involves a malicious printer driver installation process that can be executed without administrative privileges. Notably, three of the vulnerabilities remain exploitable even after patches have been applied. The exploit's mechanism involves staging a malicious driver in the Windows driver store and installing it via a client-server model. Microsoft acknowledged the security implications by issuing CVE-2021-34481. The exploit is particularly concerning for organizations using vulnerable Windows versions. The article emphasizes that the attack is straightforward and could be easily executed by attackers with limited access.

Key Points: • The 'concealed_position' exploit allows local privilege escalation on Windows systems. • It leverages multiple known vulnerabilities in printer drivers, some of which remain exploitable post-patch. • The exploit's mechanism involves a client-server model for malicious driver installation.

Ask AI about this cluster

Timeline

2020-01-24
CVE-2019-19363 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-06-09
CVE-2020-1300 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-07-16
CVE-2021-34481 published
Microsoft published CVE-2021-34481, addressing security concerns related to printer drivers.
Sploitus
2021-07-19
CVE-2021-35449 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-08-11
CVE-2021-38085 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-08-12
First public PoC for CVE-2021-34481
The first proof-of-concept for CVE-2021-34481 was made public, demonstrating the exploit's potential.
Sploitus
2023-04-11
CVE-2023-28222 published
Microsoft published CVE-2023-28222, which altered the behavior of Sysmon and affected exploitation methods.
Sploitus
2026-09-07
CVE-2023-29343 PoC released
A proof-of-concept for CVE-2023-29343, an arbitrary file write vulnerability in Sysmon, was published.
Sploitus