CVE-2022-41073
KEV ransomwaremassOut-of-Bounds Write Privilege Escalation in Microsoft Windows Print Spooler
CISA: Microsoft Windows Print Spooler Privilege Escalation Vulnerability
CVE-2022-41073 is an out-of-bounds write flaw (CWE-787) in the Microsoft Windows Print Spooler that allows a local, low-privileged user to elevate privileges (CVSS 3.1: 7.8, local attack vector, no user interaction required). It is triggered when the spooler service processes maliciously crafted content on the local machine, letting an attacker who already has a foothold run code at higher privileges. Successful exploitation effectively grants elevated (up to SYSTEM-level) control of the host, which attackers typically use to persist and move toward domain or ransomware objectives after initial access. Affected systems are essentially all listed Windows client and server editions with the Print Spooler running (enabled by default), spanning Windows 7 through Windows 11 22H2 and Windows Server 2008. The vulnerability was being actively exploited when Microsoft patched it in the November 2022 release, CISA added it to the KEV catalog on 2022-11-08 with ransomware use known, and no public PoC is cataloged despite confirmed in-the-wild exploitation.
What to do: Apply Microsoft's November 2022 security updates across all affected Windows versions, prioritizing domain controllers, file/print servers, and other shared or internet-reachable hosts, consistent with CISA's required KEV action. Where patching must wait and printing is not required, disable or restrict the Print Spooler service as an interim mitigation, noting this breaks local and network printing. Because exploitation is confirmed in the wild and linked to ransomware activity, hunt for signs of local privilege escalation on endpoints that were unpatched as of the November 2022 Patch Tuesday.
| microsoft Windows 10 | 1507, 1607, 1809, 20H2, 21H1, 21H2, 22H2 — all builds prior to the November 2022 security updates |
| microsoft Windows 11 | 21H2, 22H2 — all builds prior to the November 2022 security updates |
| microsoft Windows 7 | all builds prior to the November 2022 security updates |
| microsoft Windows 8.1 | all builds prior to the November 2022 security updates |
| microsoft Windows Server 2008 | all editions/builds prior to the November 2022 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Print Spooler Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 7, windows 8.1, windows server 2008
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H