Print Spooler Remote DLL Injection
Posted by deepcore on May 26, 2022 – 8:16 am
The print spooler service can be abused by an authenticated remote attacker to load a DLL through a crafted DCERPC request, resulting in remote code execution as NT AUTHORITYSYSTEM. This module uses the MS-RPRN vector which requires the Print Spooler service to be running.
Post a reply
You must be logged in to post a comment.