LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-41073: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 8, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Dec 9, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-41073 to its Known Exploited Vulnerabilities catalog on Nov 8, 2022, with a federal patch deadline of Dec 9, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.

CVE-2022-41073 is a privilege escalation vulnerability in the Microsoft Windows Print Spooler service. An attacker who already has some access on a system can abuse it to obtain SYSTEM-level privileges. This matters because Print Spooler is a common Windows component, and the vulnerability has been used in ransomware activity. Organizations should treat it as a priority for Windows hosts that run the service.

Public detail on exact mechanics is limited; confirm all version, configuration, and mitigation specifics against the vendor advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In the Print Spooler, this class of flaw can allow an attacker to write data outside intended memory bounds. With local or low-privilege access, the attacker can trigger the condition in the spooler process and elevate to SYSTEM privileges. The CISA summary describes an unspecified vulnerability that enables this elevation. No further exploit details are provided here; treat the issue as a local privilege-escalation path against the spooler service and validate behavior against Microsoft’s advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Print Spooler. The service commonly runs on domain controllers, print servers, and many workstations and servers that handle printing or related functions.

If the service is disabled and not required, exposure is reduced, but still confirm patch status.

How to remediate

Apply the security updates Microsoft released for this issue, following the vendor instructions exactly. CISA’s required action is to apply updates per those instructions. After patching, verify the service is running only where needed and that the update is present via your standard patch-compliance reporting.

If you can't patch immediately

Use compensating controls to limit the attack surface until the vendor update can be applied.

Reassess residual risk daily and schedule the patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities, including those used by ransomware, can lead to full system compromise and data theft or encryption. If you suspect exploitation, isolate affected hosts, preserve forensic evidence, and follow your incident-response plan. You can also run a free exposure scan of your email addresses to check whether they appear in known breach data sets and take appropriate credential-reset and monitoring steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-787
Added to CISA KEVNov 8, 2022
Federal patch deadlineDec 9, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities