Print Spooler Remote DLL Injection
Posted by deepcore on May 25, 2022 – 8:30 pm
The print spooler service can be abused by an authenticated remote attacker to load a DLL through a crafted DCERPC request, resulting in remote code execution as NT AUTHORITY\SYSTEM. This module uses the MS-RPRN vector which requires the Print Spooler service to be running.
Post a reply
You must be logged in to post a comment.