PT-2022-5458 · Microsoft · Windows 10+2

Published

2022-10-11

·

Updated

2026-06-12

·

CVE-2022-38028

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 versions prior to 10.0.10240.19507 Microsoft Windows 10 versions prior to 10.0.14393.5427 Microsoft Windows 10 versions prior to 10.0.17763.3532 Microsoft Windows 10 versions prior to 10.0.19042.2130 Microsoft Windows 10 versions prior to 10.0.19043.2130
Description The vulnerability is related to the Windows Print Spooler service and is associated with insufficient access restrictions. It allows attackers to elevate their privileges within the system. The issue has been exploited by the Russian hacking group Forest Blizzard, also known as APT28, using a custom tool called GooseEgg. This tool has been used to target organizations in Ukraine, Western Europe, and North America. The vulnerability has been used in conjunction with other exploits to gain system privileges. There have been reports of real-world incidents where this issue was exploited, including a case where attackers used the vulnerability to compromise a company's computer and steal credentials.
Recommendations For Microsoft Windows 10 versions prior to 10.0.10240.19507, update to a version that contains the fix for this vulnerability. For Microsoft Windows 10 versions prior to 10.0.14393.5427, update to a version that contains the fix for this vulnerability. For Microsoft Windows 10 versions prior to 10.0.17763.3532, update to a version that contains the fix for this vulnerability. For Microsoft Windows 10 versions prior to 10.0.19042.2130, update to a version that contains the fix for this vulnerability. For Microsoft Windows 10 versions prior to 10.0.19043.2130, update to a version that contains the fix for this vulnerability. As a temporary workaround, consider disabling the Windows Print Spooler service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06785
CVE-2022-38028

Affected Products

Windows
Windows 10
Windows Print Spooler