Junglewise Threat Intelligence

CVE-2022-38028: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

CVE-2022-38028 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2024-04-23

Technologies: Microsoft Windows, Microsoft Windows Server 2016, Microsoft Windows Server 2022, Microsoft Windows 11, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 8.1. Vendors: Microsoft.

Executive brief

The Microsoft Windows Print Spooler service contains an elevation of privilege vulnerability. An attacker can exploit this by modifying a JavaScript constraints file, allowing for the execution of arbitrary code with SYSTEM-level permissions.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.10240.19507
  • Microsoft Windows 11 up to (excluding) 10.0.22621.674
  • Microsoft Windows Server 2022 up to (excluding) 10.0.20348.1129
  • Microsoft Windows 8.1 up to (excluding) 6.3.9600.20625
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.3532
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.5427

Timeline

  • 2024-04-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-04-23: disclosed
  • 2024-04-23: exploited: Reported as exploited in the wild.

Related threats