CVE-2022-22718highunder attack

CVE-2022-22718: high-severity vulnerability in Microsoft Windows 10 Version 1507

Windows Print Spooler Elevation of Privilege Vulnerability

Published · Updated

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 18%
from disclosure to weapon123 days
Published on NVDFeb 9
1st PoC+123d
CISA KEV+69d
exploitation probability
18%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-05-10

Apply updates per vendor instructions.

In short

A flaw in Windows Print Spooler allows a local attacker with limited privileges to gain full administrative control of a computer. This is critical because it lets unauthorized users take complete control of the system.

Technical detail

Local privilege escalation vulnerability in Windows Print Spooler service; requires attacker to be authenticated on the target system with standard user privileges. Successful exploitation grants SYSTEM-level access, enabling complete system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Windows Print Spooler Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.