CVE-2022-38028: Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
Other sources
Windows Print Spooler Elevation of Privilege Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5427Patch KB5018411 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.19507Patch KB5018425 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20625Patch KB5018476 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.2130Patch KB5018410 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1129Patch KB5018421 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.20625Patch KB5018474 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3532Patch KB5018419 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.23920Patch KB5018478 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1098Patch KB5018418 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2130Patch KB5018410 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.674Patch KB5018427 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2130Patch KB5018410 - Compensating control
Discontinue use of the Microsoft Windows Print Spooler service if vendor mitigations are unavailable.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-38028?
CVE-2022-38028 has a critical severity level due to its potential to allow privilege escalation.
How do I fix CVE-2022-38028?
To fix CVE-2022-38028, apply the latest security updates provided by Microsoft for your affected Windows version.
Which versions of Windows are affected by CVE-2022-38028?
CVE-2022-38028 affects various versions of Windows, including Windows 10, Windows 11, and Windows Server editions.
What type of vulnerability is CVE-2022-38028?
CVE-2022-38028 is a privilege escalation vulnerability found in the Microsoft Windows Print Spooler service.
Can CVE-2022-38028 be exploited remotely?
CVE-2022-38028 requires local access or user privileges for exploitation, making it less likely to be exploited remotely.