CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
Description
Detects changes to the "Ports" registry key with data that includes a Windows path or a file with a suspicious extension. This could be an attempt to exploit CVE-2020-1048 - a Windows Print Spooler elevation of privilege vulnerability.
Query · sigma
selection: TargetObject|contains: \Microsoft\Windows NT\CurrentVersion\Ports Details|contains: - .bat - .com - .dll - .exe - .ps1 - .vbe - .vbs - 'C:' condition: selection
Known false positives
- New printer port install on host