ZeroHour

CVE-2022-38028

KEVmass

Local Privilege Escalation in Microsoft Windows Print Spooler (CVE-2022-38028)

CISA: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
15%p97
Published
()
KEV added
AI analysis

CVE-2022-38028 is an elevation-of-privilege vulnerability (CVSS 3.1: 7.8) in the Microsoft Windows Print Spooler, the service that manages print jobs on Windows machines. An attacker who can already run low-privileged code on a vulnerable system can exploit the flaw locally, with no user interaction required, to escalate to SYSTEM privileges and take full control of the host (high confidentiality, integrity, and availability impact). It affects a broad set of Windows releases — Windows 10 builds 1507 through 21H2, Windows 11 22H2, Windows 8.1 and Windows RT 8.1, and Windows Server 2012, 2016, and 2019 — so most unpatched Windows estates are in scope. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-04-23 (ransomware use unknown), and public reporting attributes active use to the Russia-linked APT28 group, whose custom 'GooseEgg' tool leverages this NSA-reported flaw to run payloads with elevated privileges; Microsoft shipped the fix in its April 2024 Patch Tuesday. EPSS is 14.9% (96th percentile), indicating elevated near-term exploitation risk on top of the already-observed APT28 activity.

What to do: Apply Microsoft's security updates for the affected Windows releases (fixed in the April 2024 Patch Tuesday); as a KEV entry, CISA requires applying vendor mitigations or discontinuing use of unpatched versions. On servers where printing is not required, disabling the Print Spooler service removes the local attack path. Given confirmed APT28 use of the 'GooseEgg' exploit, hunt for related activity on unpatched hosts and prioritize patching endpoints belonging to organizations and users targeted by APT28.

Affected
Microsoft Windows 101507, 1607, 1809, 20H2, 21H1, 21H2
Microsoft Windows 1122H2
Microsoft Windows 8.1all supported builds
Microsoft Windows RT 8.1all supported builds
Microsoft Windows Server 2012all supported builds
Microsoft Windows Server 2016all supported builds
Microsoft Windows Server 2019all supported builds
Estimated exposure
masshundreds of millions of Windows 10/11 endpoints plus millions of Windows Server hosts (every unpatched install of the listed releases) — The Print Spooler service is present by default on the listed Windows client and server releases, which collectively run on hundreds of millions of enterprise and consumer machines worldwide, so any system not yet running the vendor fixes…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Print Spooler Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 11 22h2, windows 8.1, windows rt 8.1, windows server 2012, windows server 2016, windows server 2019
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news