CVE-2022-38028 - Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Project:Microsoft
Product:Windows
Date Added:2024-04-23Due Date:2024-05-14
Vulnerability Name
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Description
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38028
https://nvd.nist.gov/vuln/detail/CVE-2022-38028
Related News Articles
PrintNightmare Aftermath: Windows Print Spooler is Better. What's Next?January 30, 2025
Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'November 23, 2024