ZeroHour

CVE-2022-41073

KEV ransomwaremass

Out-of-Bounds Write Privilege Escalation in Microsoft Windows Print Spooler

CISA: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p82
Published
()
KEV added
AI analysis

CVE-2022-41073 is an out-of-bounds write flaw (CWE-787) in the Microsoft Windows Print Spooler that allows a local, low-privileged user to elevate privileges (CVSS 3.1: 7.8, local attack vector, no user interaction required). It is triggered when the spooler service processes maliciously crafted content on the local machine, letting an attacker who already has a foothold run code at higher privileges. Successful exploitation effectively grants elevated (up to SYSTEM-level) control of the host, which attackers typically use to persist and move toward domain or ransomware objectives after initial access. Affected systems are essentially all listed Windows client and server editions with the Print Spooler running (enabled by default), spanning Windows 7 through Windows 11 22H2 and Windows Server 2008. The vulnerability was being actively exploited when Microsoft patched it in the November 2022 release, CISA added it to the KEV catalog on 2022-11-08 with ransomware use known, and no public PoC is cataloged despite confirmed in-the-wild exploitation.

What to do: Apply Microsoft's November 2022 security updates across all affected Windows versions, prioritizing domain controllers, file/print servers, and other shared or internet-reachable hosts, consistent with CISA's required KEV action. Where patching must wait and printing is not required, disable or restrict the Print Spooler service as an interim mitigation, noting this breaks local and network printing. Because exploitation is confirmed in the wild and linked to ransomware activity, hunt for signs of local privilege escalation on endpoints that were unpatched as of the November 2022 Patch Tuesday.

Affected
microsoft Windows 101507, 1607, 1809, 20H2, 21H1, 21H2, 22H2 — all builds prior to the November 2022 security updates
microsoft Windows 1121H2, 22H2 — all builds prior to the November 2022 security updates
microsoft Windows 7all builds prior to the November 2022 security updates
microsoft Windows 8.1all builds prior to the November 2022 security updates
microsoft Windows Server 2008all editions/builds prior to the November 2022 security updates
Estimated exposure
masshundreds of millions of Windows devices (Print Spooler is enabled by default on most Windows client and server installations) — Windows' installed base runs to roughly a billion-plus devices and the Print Spooler service starts by default on Windows clients and servers, so essentially every unpatched Windows endpoint and server is plausibly vulnerable — an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Print Spooler Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 7, windows 8.1, windows server 2008
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news