CVE-2022-38028

HIGH KEV

Windows Print Spooler - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-38028 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 23, 2024.

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Scores

CVSS v3 7.8
EPSS 0.0391
EPSS Percentile 88.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2024-04-23
VulnCheck KEV 2024-04-22
InTheWild.io 2024-04-23
ENISA EUVD EUVD-2022-40634
Status published
Products (14)
microsoft/windows_10_1507 < 10.0.10240.19507
microsoft/windows_10_1607 < 10.0.14393.5427 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.3532
microsoft/windows_10_20h2 < 10.0.19042.2130 (2 CPE variants)
microsoft/windows_10_21h1 < 10.0.19043.2130
microsoft/windows_10_21h2 < 10.0.19044.2130
microsoft/windows_11_22h2 < 10.0.22621.674
microsoft/windows_8.1 < 6.3.9600.20625
microsoft/windows_rt_8.1 < 6.3.9600.20625
microsoft/windows_server_2012
... and 4 more
Published Oct 11, 2022
KEV Added Apr 23, 2024
Tracked Since Feb 18, 2026