CVE-2022-38028:Windows Print Spooler Elevation of Privilege Vulnerability (CVE-2022-38028) allows an attacker to gain elevated privileges on affected systems.

splash
Back

Description Preview

CVE-2022-38028 is a vulnerability in the Windows Print Spooler service that can be exploited to achieve elevation of privilege. An attacker who successfully exploits this vulnerability could run arbitrary code with elevated privileges on the affected system. This could allow the attacker to install programs; view, change, or delete data; or create new accounts with full user rights. The vulnerability affects various versions of Windows, including Windows 10, Windows Server 2019, Windows Server 2022, and several others. The issue arises from improper handling of requests by the Print Spooler service.

Overview

  • CVE ID: CVE-2022-38028
  • Published Date: October 11, 2022
  • Last Updated: January 2, 2025
  • Severity: High (CVSS Base Score: 7.8)
  • Impact: Elevation of Privilege
  • Affected Products:
    • Windows 10 (various versions)
    • Windows Server 2019
    • Windows Server 2022
    • Windows 11 (various versions)
    • Windows 8.1
    • Windows Server 2012 and 2012 R2
    • Windows Server 2016

Remediation

To mitigate the risks associated with CVE-2022-38028, Microsoft recommends applying the latest security updates for affected Windows versions. Users should ensure that their systems are updated to versions that are not vulnerable:

  • For Windows 10 Version 1809, ensure the version is updated to 10.0.17763.3532 or later.
  • For Windows Server 2019, ensure the version is updated to 10.0.17763.3532 or later.
  • For other affected versions, refer to the specific version requirements listed in the CVE details.

Additionally, organizations should consider disabling the Print Spooler service if it is not required, and implement strict access controls to limit the ability to exploit this vulnerability.

References

Early Warning

Customers using Armis Early Warning were notified about this vulnerability before it appeared in CISA's Known Exploited Vulnerabilities Catalog, enabling them to assess their exposure and act proactively. Armis offers these examples of CVEs already included in CISA KEV for potential customers. Click here to learn how to receive alerts earlier.

Armis Alert Date
Oct 11, 2022
CISA KEV Date
Apr 23, 2024
560days early

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Public Administration: Medium
    Public Administration
  2. Manufacturing: Medium
    Manufacturing
  3. Health Care & Social Assistance: Medium
    Health Care & Social Assistance
  4. Educational Services: Medium
    Educational Services
  5. Transportation & Warehousing: Medium
    Transportation & Warehousing
  6. Finance and Insurance: Medium
    Finance and Insurance
  7. Retail Trade: Medium
    Retail Trade
  8. Arts, Entertainment & Recreation: Medium
    Arts, Entertainment & Recreation
  9. Professional, Scientific, & Technical Services: Medium
    Professional, Scientific, & Technical Services
  10. Utilities: Medium
    Utilities
  11. Other Services (except Public Administration): Low
    Other Services (except Public Administration)
  12. Information: Low
    Information
  13. Management of Companies & Enterprises: Low
    Management of Companies & Enterprises
  14. Accommodation & Food Services: Low
    Accommodation & Food Services
  15. Agriculture, Forestry Fishing & Hunting: Low
    Agriculture, Forestry Fishing & Hunting
  16. Mining: Low
    Mining
  17. Real Estate Rental & Leasing: Low
    Real Estate Rental & Leasing
  18. Construction: Low
    Construction
  19. Administrative, Support, Waste Management & Remediation Services: Low
    Administrative, Support, Waste Management & Remediation Services
  20. Wholesale Trade: Low
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background