Sploitus
New Local Privilege Escalation Exploit Targets Windows Print Drivers
Article Content
The 'concealed_position' exploit, revealed at DEF CON 29, allows low-privileged users to escalate privileges to SYSTEM on Windows by exploiting vulnerabilities in printer drivers. It utilizes four known CVEs: CVE-2021-35449, CVE-2021-38085, CVE-2019-19363, and CVE-2020-1300. The exploit involves a malicious printer driver installation process that can be executed without administrative privileges. Notably, three of the vulnerabilities remain exploitable even after patches have been applied. The exploit's mechanism involves staging a malicious driver in the Windows driver store and installing it via a client-server model. Microsoft acknowledged the security implications by issuing CVE-2021-34481. The exploit is particularly concerning for organizations using vulnerable Windows versions. The article emphasizes that the attack is straightforward and could be easily executed by attackers with limited access.
Key Points: • The 'concealed_position' exploit allows local privilege escalation on Windows systems. • It leverages multiple known vulnerabilities in printer drivers, some of which remain exploitable post-patch. • The exploit's mechanism involves a client-server model for malicious driver installation.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.