Junglewise Threat Intelligence

CVE-2022-22718: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

CVE-2022-22718 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-04-19

Technologies: Microsoft Windows Server 2022, Microsoft Windows 7, Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows Server 2019, Microsoft Windows 11, Microsoft Windows 8.1, Microsoft Windows Server 2008, Microsoft Windows 10, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

Microsoft Windows Print Spooler contains an elevation of privilege vulnerability that allows a local attacker to gain system-level privileges. The flaw is caused by insufficient information handling within the spooler service.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.19044.1526
  • Microsoft Windows 11 up to (excluding) 10.0.22000.493
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.524
  • Microsoft Windows 7 Service Pack 1
  • Microsoft Windows 8.1 all
  • Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
  • Microsoft Windows Server 2012 all
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4946
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2565

Timeline

  • 2022-04-19: disclosed
  • 2022-04-19: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-10: other: CISA remediation due date

Related threats