It’s rather unusual for us to report a 24-year Windows vulnerability, but the vulnerability found affects all versions of the operating system since Windows NT 4 – and this edition was published in 1996.

A hole called PrintDemon, which was discovered and published by security researchers Alex Ionescu and Yarden Shafi (via ZDNet), is located in the Windows print queue manager. This is the component that is primarily responsible for managing print operations.

A service can perform various operations: it can send data to a USB / parallel port and, therefore, to a physically connected printer. In addition, through it you can access the TCP port to send data to a network printer. The third option is to send the work to a local file so that you can save it for later.

Local privilege escalation

The security researcher has discovered an error that can be used to hack the functionality of the Windows print spooler. Anyone who uses the vulnerability can create a back door that will be permanent. The good news is that you cannot use this space over the Internet. But you need local access to your computer.

Therefore, PrintDemon is a vulnerability called Local Privilege Elevation (LPE). Theoretically, this means that it needs to be activated locally. But as soon as this is done, the attacker will gain wide administrator rights.

You do not need to worry: the vulnerability is released after it is fixed. Users with the current Windows operating system should install the fixes provided the day before yesterday. PrintDemon is also officially known as CVE-2020-1048, and it was addressed yesterday with the fixes.

