The Windows Print Spooler runs by default on workstations and servers, including domain controllers, and exposes remote RPC interfaces (MS-RPRN, MS-PAR) to any authenticated user. It has been one of the most reliably abused services in Windows for years, in two distinct ways: it can be made to authenticate to an attacker (coercion), and it can be made to load an attacker's driver DLL as SYSTEM (code execution).
A long history of abuse#
The spooler's offensive value has compounded over several waves, and each is still useful where patching or hardening lagged:
- 2018, PrinterBug / SpoolSample: Lee Christensen showed that
RpcRemoteFindFirstPrinterChangeNotificationExforces a target to authenticate back over SMB, a dependable coercion primitive still used to feed relay and delegation attacks. - 2021, PrintNightmare: a flaw in
RpcAddPrinterDriverExand Point and Print let an unprivileged user load a driver DLL and execute as SYSTEM, both remotely and locally, covered under Point and Print. - 2022, SpoolFool and later spooler privilege-escalation bugs continued the pattern of local SYSTEM through the same service.
Pages#
- Coercion: forcing a machine to authenticate with the PrinterBug, to feed relay and delegation.
- Point and Print: loading a driver to execute as SYSTEM, remotely and locally.