itm4n/PrintSpoofer
Abusing impersonation privileges through the "Printer Bug" observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 0
- Release rhythm 8
- Longevity 100
Flags: archived no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2318
- days_rel: n/a
- days_push: 2183
- n_releases_24m: 0
Adoption not part of the score
2268 stars · 367 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
PrintSpoofer is a Windows privilege escalation tool that abuses SeImpersonatePrivilege via the Print Spooler 'Printer Bug' to escalate from LOCAL/NETWORK SERVICE to SYSTEM on Windows 10 and Server 2016/2019. It spawns a SYSTEM process running a custom command, either interactively, non-interactively, or on a specific desktop session.
Use cases
- escalate from service account to SYSTEM on Windows Server 2019
- get a SYSTEM reverse shell from a webshell
- spawn a SYSTEM command prompt over WinRM or wmiexec
- exploit SeImpersonatePrivilege when Juicy Potato fails on modern Windows
- run PowerShell as NT AUTHORITY\SYSTEM from a bind shell
When to choose
- you hold SeImpersonatePrivilege on Windows 10 or Server 2016/2019 where potato attacks no longer work
- you need a quick, reliable SYSTEM shell during a pentest without extra dependencies
When to avoid
- you are on legacy Windows versions where Juicy Potato works
- you need a maintained tool - the project has had no releases since 2020 and is patched on fully updated systems
- you are doing defensive auditing rather than offensive exploitation
Facets
cli-tool · maturity maintenance
security penetration-testing cli security penetration-testing windows windows cli privilege-escalation seimpersonateprivilege print-spooler system-shell post-exploitation red-team
2 sources
- readme: https://github.com/itm4n/PrintSpoofer · fetched 2026-08-28 · 3ee225d6aaea
- homepage: https://itm4n.github.io/printspoofer-abusing-impersonate-privileges/ · fetched 2026-08-29 · 3ab085e475ec
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| itm4n/PrintSpoofer | main | 10 |
For agents
markdown · JSON · MCP: product_card(name="itm4n/PrintSpoofer")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem