Vulnerability record · CVE-2022-38028 · published 11 October 2022
CVE-2022-38028: Windows Print Spooler local privilege escalation
Microsoft · Windows 10 1507
CVE-2022-38028 is an elevation of privilege flaw in the Windows Print Spooler. A local attacker with low privileges can exploit it to gain higher rights on the host. The record gives no root-cause detail beyond the generic description and an uninformative CWE entry.
Description
Windows Print Spooler Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed local privilege escalation with high CVSS impact, though it requires an existing local foothold rather than remote access.
What it is
CVE-2022-38028 is an elevation of privilege flaw in the Windows Print Spooler. A local attacker with low privileges can exploit it to gain higher rights on the host. The record gives no root-cause detail beyond the generic description and an uninformative CWE entry.
Impact
An attacker who already holds a low-privileged local account can escalate to higher integrity, confidentiality and availability impact on the affected system, per the CVSS vector. This enables full control of the host from an unprivileged foothold.
Attack surface
The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already have code execution or an account on the target machine. It is not remotely reachable on its own.
Exploitation
CISA added it to KEV on 2024-04-23 with a remediation due date of 2024-05-14, indicating exploitation in the wild. EPSS 30-day probability is about 0.149 (96.5th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update for CVE-2022-38028 on all listed Windows client and server versions.
- If patching cannot be done immediately, follow the vendor mitigation guidance referenced in the CISA KEV required action.
- Restrict and monitor local accounts and administrative rights to limit the value of a local privilege escalation.
- Consider disabling or tightly controlling the Print Spooler service on hosts that do not need printing.
Detection
- Monitor for unexpected privilege changes or new high-integrity processes spawned from low-privileged contexts on print servers and endpoints.
- Audit Print Spooler service activity and unusual spooler-related file or registry writes.
- Alert on exploitation attempts or post-exploitation tooling tied to print spooler privilege escalation.
- Track patch state for the affected Windows builds and flag unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-38028 to the Known Exploited Vulnerabilities catalog on 23 April 2024 as "Microsoft Windows Print Spooler Privilege Escalation Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 14 May 2024.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38028 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-38028 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-38028 | US Government Resource |
Track CVE-2022-38028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-38028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.