Executive brief
The Microsoft Windows Print Spooler service contains an elevation of privilege vulnerability. An attacker can exploit this by modifying a JavaScript constraints file, allowing for the execution of arbitrary code with SYSTEM-level permissions.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19507
- Microsoft Windows 11 up to (excluding) 10.0.22621.674
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.1129
- Microsoft Windows 8.1 up to (excluding) 6.3.9600.20625
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.3532
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.5427
Timeline
- 2024-04-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-04-23: disclosed
- 2024-04-23: exploited: Reported as exploited in the wild.