CISA Known Exploited Vulnerability

CVE-2022-38028

Microsoft · Windows

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.

Required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.