Executive brief
Microsoft Windows Print Spooler contains an elevation of privilege vulnerability that allows a local attacker to gain system-level privileges. The flaw is caused by insufficient information handling within the spooler service.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.19044.1526
- Microsoft Windows 11 up to (excluding) 10.0.22000.493
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.524
- Microsoft Windows 7 Service Pack 1
- Microsoft Windows 8.1 all
- Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
- Microsoft Windows Server 2012 all
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4946
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2565
Timeline
- 2022-04-19: disclosed
- 2022-04-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-10: other: CISA remediation due date