← back
CVE-2022-41073

Windows Print Spooler Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 2.4%● KEVCWE-787
Vexday Risk Score
71High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 2.4%KEV simPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
08 Nov 2022Active exploitation (CISA KEV)
09 Nov 2022Published on NVD
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows Print Spooler allows a local attacker to run code with higher privileges than their account normally allows. This is dangerous because an attacker with basic user access could take full control of the system.

Technical detail

Out-of-bounds write vulnerability in Windows Print Spooler service enables local privilege escalation via malformed print requests. An authenticated local attacker can exploit this to execute arbitrary code with SYSTEM privileges, requiring no user interaction post-exploitation.

Summary generated and translated by AI from the official description.
Windows Print Spooler Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →