← back
CVE-2022-21999

Windows Print Spooler Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 41.7%● KEVCWE-22CWE-59
In short

A flaw in Windows Print Spooler allows a local attacker to gain higher system privileges on an affected computer. An attacker who exploits this vulnerability could run malicious code with administrative rights.

Technical detail

A path traversal vulnerability (CWE-22) combined with insecure file operations (CWE-59) in the Windows Print Spooler service allows a local authenticated attacker to execute arbitrary code with SYSTEM privileges. The vulnerability requires local access and exploitation can lead to complete system compromise.

Summary generated and translated by AI from the official description.
Windows Print Spooler Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →