LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22718: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 19, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22718 to its Known Exploited Vulnerabilities catalog on Apr 19, 2022, with a federal patch deadline of May 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.

CVE-2022-22718 is a privilege escalation vulnerability in the Microsoft Windows Print Spooler. An attacker who can already run code in a less-privileged context may be able to elevate to higher privileges on the affected system. Privilege escalation flaws matter because they turn limited footholds into full control of a host, enabling further lateral movement, persistence, or data access. Specifics such as exact builds and attack preconditions must be confirmed against the vendor advisory.

CISA describes the issue as an unspecified vulnerability in the Windows Print Spooler that allows privilege escalation and directs organizations to apply updates per Microsoft’s instructions. Known ransomware use is not documented for this CVE.

How it works

The Print Spooler is a core Windows service that manages print jobs and related printer configuration. Privilege-escalation vulnerabilities in this component typically arise when the service mishandles requests, objects, or configuration data in a way that lets a lower-privileged process influence higher-privileged operations. An attacker who already has a foothold on the system—through phishing, a separate vulnerability, or a compromised account—could abuse the flaw to obtain elevated rights on that same host.

Because the CWE is not specified in the available record, defenders should treat this as a classic local privilege-escalation issue against a privileged Windows service. Exact exploitation mechanics, required access rights, and any race or object-handling details are not provided here and must be taken only from the vendor advisory. Do not assume remote code execution; the documented impact is privilege escalation.

Am I affected? How to find it in your systems

The Print Spooler runs by default on many Windows clients and servers, including domain controllers and print servers. Inventory every Windows endpoint and server, then determine whether the Print Spooler service is present and running. Check installed updates and build information against the Microsoft advisory for CVE-2022-22718 to identify systems that still lack the fix.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2022-22718 exactly as directed in the vendor advisory and in line with CISA’s required action to apply updates per vendor instructions. Prioritize domain controllers, print servers, jump hosts, and any system where untrusted users or processes can run code.

If you can't patch immediately

Until the vendor update is installed, reduce exposure with compensating controls. These do not replace the patch.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are commonly used after initial access to deepen a compromise and reach sensitive data. If you have reason to believe systems were exposed before patching, follow your incident-response process: isolate affected hosts, preserve logs and memory as appropriate, rotate credentials that may have been accessible, and hunt for persistence and lateral movement. You can also run a free exposure scan of your email addresses against known breach data to see whether associated credentials or identities appear in prior public breaches, then force resets and enable stronger authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVApr 19, 2022
Federal patch deadlineMay 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities