HIGH

CVE-2022-21999

Microsoft Windows 10 1507 2022-02-09 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in the Windows Print Spooler service. An attacker with low-privilege access can exploit the Print Spooler to gain SYSTEM-level privileges, potentially executing arbitrary code with the highest Windows privileges.

Mitigation

Apply the Microsoft security update KB5009557 (or subsequent superseding patches) for CVE-2022-21999. If the Print Spooler service is not required in the environment, it can be disabled to eliminate the attack surface.

Patch Commit

Weakness (CWE)

CWE-22 Path Traversal
CWE-59 Link Following (Symlink)

EPSS Score

41.01%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE