Vulnerability record · CVE-2022-21999 · published 9 February 2022
CVE-2022-21999: Windows Print Spooler elevation of privilege via path traversal and link following
Microsoft · Windows 10 1507
CVE-2022-21999 is an elevation of privilege flaw in the Windows Print Spooler, classified as path traversal (CWE-22) and link following (CWE-59). A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because Print Spooler flaws have been widely used to move from a normal user to SYSTEM and are known to be exploited in ransomware operations.
Description
Windows Print Spooler Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in CISA KEV with known ransomware use and a high EPSS score, but it requires local low-privileged access rather than being remotely exploitable, placing it below critical.
What it is
CVE-2022-21999 is an elevation of privilege flaw in the Windows Print Spooler, classified as path traversal (CWE-22) and link following (CWE-59). A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because Print Spooler flaws have been widely used to move from a normal user to SYSTEM and are known to be exploited in ransomware operations.
Impact
An attacker who successfully exploits the flaw gains elevated privileges on the affected Windows system, with high impact to confidentiality, integrity and availability per the CVSS vector. In practice this means full control of the host from a low-privileged starting point.
Attack surface
The CVSS vector is AV:L/AC:L/PR:L/UI:N, so the flaw is reached locally by an attacker who already holds low privileges on the machine; no user interaction is required. It is not remotely reachable and does not require prior administrative rights.
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and EPSS gives a 30-day exploitation probability of about 0.42 (98.6th percentile), indicating active exploitation is expected. No public exploit code or specific ransomware group is named in the record.
What to do
- Apply the Microsoft security update for CVE-2022-21999 on all affected Windows versions as the first action.
- Prioritize patching of systems past the CISA KEV due date of 2022-04-15, especially servers and endpoints running the Print Spooler service.
- Disable the Print Spooler service on hosts that do not need printing, and restrict who can install or manage printers.
- Limit local interactive logon and low-privileged account use on sensitive systems to reduce the pool of accounts that can trigger the flaw.
- Monitor Microsoft advisories for any follow-up Print Spooler hardening guidance.
Detection
- Monitor for unexpected creation or modification of files and links in spooler-related directories such as C:\Windows\System32\spool and driver folders.
- Alert on Print Spooler service crashes or restarts, which are a common side effect of spooler exploitation attempts.
- Track privilege escalation events where a low-privileged process spawns a SYSTEM-level process shortly after spooler activity.
- Correlate local logon events from non-administrative accounts with subsequent service or driver installation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-21999 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Microsoft Windows Print Spooler Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-21999 | US Government Resource |
Track CVE-2022-21999 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21999), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.