HIGH

CVE-2022-41073

Microsoft Windows 10 1507 2022-11-09 CVSS v3.1
CVSS
7.8
KEV

Description

Windows Print Spooler Elevation of Privilege Vulnerability

Summary dbcve.org

This is an elevation of privilege vulnerability in the Windows Print Spooler service. The Print Spooler runs with elevated system privileges and improper handling of certain operations allows an authenticated attacker to gain higher-level Windows permissions.

Mitigation

Apply the Microsoft security update for CVE-2022-41073. If the Print Spooler service is not required, it can be disabled to reduce the attack surface.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

2.28%
Probability of exploitation in next 30 days
82.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE