Record summary

CVE-2022-22718 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC. CISA lists CVE-2022-22718 in KEV.

Description

Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22717.

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Apr 19, 2022 · CISA
VulnCheck KEV
Listed · Apr 19, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

Showing 12 of 26
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List10.0.10240.0 to < 10.0.10240.19204affected
CVE List10.0.14393.0 to < 10.0.14393.4946affected
CVE List10.0.17763.0 to < 10.0.17763.2565affected
10.0.0 to < 10.0.17763.2565affected
CVE List10.0.0 to < 10.0.18363.2094affected
CVE List10.0.0 to < 10.0.19042.1526affected
CVE List10.0.0 to < 10.0.19043.1526affected
CVE List10.0.19043.0 to < 10.0.19044.1526affected
CVE List10.0.0 to < 10.0.22000.493affected
CVE List6.1.0 to < 6.1.7601.25860affected
CVE List6.1.0 to < 6.1.7601.25860affected
CVE List6.3.0 to < 6.3.9600.20269affected

Proofs of concept

2

Catalogued exploits

MetasploitCVE-2022-21999 SpoolFool PrivescMetasploit exploitby Oliver Lyak +1 moreNot analyzed1 file

Ruby · linked to 2 vulnerabilities

Metasploit

PoC details

Repository PoCs

GitHubahmetfurkans/CVE-2022-22718Repository PoCby ahmetfurkansStars: 0Not analyzed2 files

221.6 KiB

GitHub

PoC details

References

4