HIGH
CVE-2022-41073
CVSS
7.8
KEV
Description
Windows Print Spooler Elevation of Privilege Vulnerability
Summary dbcve.org
This is an elevation of privilege vulnerability in the Windows Print Spooler service. The Print Spooler runs with elevated system privileges and improper handling of certain operations allows an authenticated attacker to gain higher-level Windows permissions.
Mitigation
Apply the Microsoft security update for CVE-2022-41073. If the Print Spooler service is not required, it can be disabled to reduce the attack surface.
Weakness (CWE)
CWE-787
Out-of-bounds Write
EPSS Score
2.28%
Probability of exploitation in next 30 days
82.4th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41073
Patch, Vendor Advisory
http://packetstormsecurity.com/files/174528/Microsoft-Windows-Privilege-Escalation.html
Third Party Advisory, VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41073
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.