PT-2022-1661 · Microsoft · Windows Print Spooler+1

Edwardzpeng

+4

·

Published

2022-02-08

·

Updated

2025-05-15

·

CVE-2022-21999

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Print Spooler versions prior to the fixed version
Description The issue is related to errors in security settings, allowing an attacker to elevate their privileges. This can affect the system, potentially leading to further exploitation. The vulnerability has been exploited in real-world incidents, including ransomware attacks by groups such as LockBit 2.0. Industries affected include Telco, Retail, Financial, and Government, primarily in Cyprus and Russia.
Recommendations For Windows Print Spooler, apply the official fix to resolve the issue. As a temporary workaround, consider restricting access to the Print Spooler service until the patch is applied. Avoid using vulnerable functions related to the Print Spooler until the issue is resolved.

Exploit

Fix

LPE

Improper Privilege Management

Path traversal

Link Following

Weakness Enumeration

Related Identifiers

BDU:2022-00911
CVE-2022-21999

Affected Products

Windows
Windows Print Spooler