HIGH

CVE-2022-38028

Microsoft Windows 10 1507 2022-10-11 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Summary dbcve.org

CVE-2022-38028 is an Elevation of Privilege vulnerability in the Windows Print Spooler service that allows a local authenticated attacker to gain elevated system privileges. The vulnerability exploits a flaw in how the Print Spooler handles certain printer driver operations, enabling privilege escalation from a low-privileged user context to NT AUTHORITY\SYSTEM.

Mitigation

Apply the relevant Microsoft security update for CVE-2022-38028. If the Print Spooler service is not required in the environment, consider disabling it to reduce the attack surface.

Patch Commit

EPSS Score

14.95%
Probability of exploitation in next 30 days
96.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE