Vulnerability record · CVE-2022-22718 · published 9 February 2022
CVE-2022-22718: Windows Print Spooler local privilege escalation
Microsoft · Windows 10 1507
CVE-2022-22718 is an elevation of privilege flaw in the Windows Print Spooler. A local attacker with low privileges can exploit it to gain higher privileges on the host. It affects a broad range of Windows client and server versions, making it relevant to most Windows estates.
Description
Windows Print Spooler Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a high EPSS percentile, though it requires local low-privileged access rather than being remotely exploitable.
What it is
CVE-2022-22718 is an elevation of privilege flaw in the Windows Print Spooler. A local attacker with low privileges can exploit it to gain higher privileges on the host. It affects a broad range of Windows client and server versions, making it relevant to most Windows estates.
Impact
An attacker who already holds a low-privileged account can escalate to SYSTEM-level rights on the affected machine. That level of access enables full control of the host, including credential theft and disabling of security controls.
Attack surface
The CVSS vector is AV:L/PR:L/UI:N, so the flaw is reached locally by an authenticated low-privileged user and requires no user interaction. It is not remotely reachable over the network per the supplied vector.
Exploitation
CISA added it to the KEV catalog on 2022-04-19 with a remediation due date of 2022-05-10, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.18464 (97th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for CVE-2022-22718 across all listed Windows client and server versions.
- Prioritize patching of internet-facing and multi-user systems such as terminal servers and Windows Server 2019/2022 hosts.
- Restrict local logon and interactive access to only trusted users to reduce the pool of accounts that can trigger the flaw.
- Where the Print Spooler service is not required, disable it to remove the attack surface.
- Track KEV remediation deadlines and verify patching through inventory or vulnerability scanning.
Detection
- Monitor for unexpected creation of SYSTEM-level processes or services spawned from low-privileged user sessions.
- Alert on suspicious access or modification of Print Spooler service binaries and spooler-related registry keys.
- Correlate local privilege escalation events (for example, token or process creation anomalies) with recent spooler activity.
- Audit hosts still running unpatched Windows builds from the affected product list.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22718 to the Known Exploited Vulnerabilities catalog on 19 April 2022 as "Microsoft Windows Print Spooler Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 May 2022.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22718 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22718 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22718 | US Government Resource |
Track CVE-2022-22718 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22718), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.