LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-21999: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-21999 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

CVE-2022-21999 is a privilege-escalation vulnerability in the Microsoft Windows Print Spooler. An attacker who already has a foothold on a system can abuse it to gain higher privileges. CISA notes that this issue has been used in ransomware activity, so unpatched Windows hosts that run the spooler remain a practical risk until updates are applied per vendor instructions.

Public detail on the exact mechanics is limited; defenders should treat it as an elevation-of-privilege flaw in a core Windows service and confirm all version, configuration, and patch specifics directly against the Microsoft advisory.

How it works

The vulnerability is associated with CWE-40 and CWE-1386, classes that commonly involve improper handling of paths or temporary files. In the Print Spooler, such weaknesses can let a lower-privileged process influence files or operations that the spooler performs with higher privileges.

An attacker who can already execute code or interact with the spooler on the local system abuses the flaw to escalate to SYSTEM or an equivalent high-privilege context. From there they can disable defenses, move laterally, or deploy further payloads. Exact exploit steps are not detailed in the supplied facts; treat any public proof-of-concept claims cautiously and validate behavior only in controlled lab conditions against the vendor’s description.

Am I affected? How to find it in your systems

The Print Spooler runs by default on most Windows clients and on many servers that provide print services or act as print servers. It is also present on domain controllers and other infrastructure hosts unless deliberately disabled.

How to remediate

Apply the security updates Microsoft released for this CVE as the primary fix. Follow the vendor’s installation order and reboot guidance, then verify the update is present with your patch-management console or by checking the system’s update history.

If you can't patch immediately

Reduce exposure until the vendor update can be deployed:

If your data may have been exposed

Privilege-escalation flaws that have been used in ransomware campaigns frequently precede data theft or encryption. If you discover exploitation or cannot rule it out, follow your incident-response plan: isolate affected hosts, preserve volatile evidence, and assess whether credentials or sensitive data were accessed. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts already appear in public dumps, then force password resets and enable phishing-resistant MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-40
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities