CVE-2021-1675-PrintNightmare

Working PowerShell POC

Powershell script is copied from https://github.com/calebstewart/CVE-2021-1675 Respect for Caleb Stewart and John Hammond.

I just wanted to have working poc close at hand. Ive added my custom DLL and an obfuscated version of powershell script.

Obfuscated script loads DLL named "printed.dll" from "C:\windows\tracing" directory.