Executive brief
Microsoft Windows Print Spooler contains an elevation of privilege vulnerability involving improper limitation of a pathname (path traversal) and improper link resolution (link following). An attacker who successfully exploits this vulnerability could gain elevated system privileges.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.19044.1526
- Microsoft Windows 11 up to (excluding) 10.0.22000.493
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.524
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4946
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2565
Timeline
- 2022-03-25: disclosed
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog