CVE-2022-21999
published 2022-02-09CVE-2022-21999: Windows Print Spooler Elevation of Privilege Vulnerability
PriorityP187high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
41.68%
98.5th percentile
Windows Print Spooler Elevation of Privilege Vulnerability
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19204 | 10.0.10240.19204 |
| microsoft | windows_10_1607 | < 10.0.14393.4946 | 10.0.14393.4946 |
| microsoft | windows_10_1809 | < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_1909 | < 10.0.18363.2094 | 10.0.18363.2094 |
| microsoft | windows_10_20h2 | < 10.0.19042.1526 | 10.0.19042.1526 |
| microsoft | windows_10_21h1 | < 10.0.19043.1526 | 10.0.19043.1526 |
| microsoft | windows_10_21h2 | < 10.0.19044.1526 | 10.0.19044.1526 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19204 | 10.0.10240.19204 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.4946 | 10.0.14393.4946 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2565 | 10.0.17763.2565 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2094 | 10.0.18363.2094 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1526 | 10.0.19042.1526 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1526 | 10.0.19043.1526 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1526 | 10.0.19044.1526 |
| microsoft | windows_11_21h2 | < 10.0.22000.493 | 10.0.22000.493 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.493 | 10.0.22000.493 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25860 | 6.1.7601.25860 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25860 | 6.1.7601.25860 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20269 | 6.3.9600.20269 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25860 | 6.1.7601.25860 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21374 | 6.0.6003.21374 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23605 | 6.2.9200.23605 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect SpoolFool exploitation by monitoring for creation of the payload drop path C:\Windows\System32\spool\drivers\x64\4 combined with SetPrinterDataEx() calls using the CopyFiles\ registry key, which triggers DLL load as SYSTEM. ↗
- →Monitor for creation of a Windows service named 'WMI Provider' loading wmipd.dll from c:\windows\system32\wmipd.dll as an indicator of OwlProxy deployment. ↗
- →Detect OwlProxy C2 activity by alerting on inbound HTTPS requests to URL prefixes matching /topics/ and /topics/pp/ on port 443, particularly those containing query parameters s?pa= (command execution) or s?pp= (proxy setup). ↗
- →Alert on SpoolFool post-exploitation activity: creation of a local administrator account with username 'admin' and password 'Passw0rd!' via the Windows Print Spooler exploit. ↗
- →Detect SpoolDirectory abuse: monitor for SetPrinterDataEx() calls that set SpoolDirectory to a UNC path or directory junction, which is the prerequisite step for CVE-2022-21999 exploitation. ↗
- ·The SpoolDirectory path (C:\Windows\System32\spool\drivers\x64\4) is only created if it does not already exist; the exploit relies on the print spooler reinitializing to trigger directory and DLL creation, so detection must account for the reinitialization step. ↗
- ·OwlProxy's wmipd.dll variant observed in CL-STA-0046 differs slightly from the April 2020 Taiwan samples; hash-based detection of earlier OwlProxy samples may not match this newer variant. ↗
- ·EarthWorm (ew.exe) is a publicly available SOCKS tunneler not inherently malicious; detections based solely on the binary name or tool behavior may produce false positives in legitimate research or admin contexts. ↗
- ·The AspxSpy web shell used is publicly available and not exclusive to Gelsemium; detections on this web shell alone should not be used for attribution. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
cisa·2022-03-25·CVSS 7.8
CVE-2022-21999 [HIGH] CWE-40 Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-21999
Remediation Due Date: 2022-04-15
Microsoft
Windows Print Spooler Elevation of Privilege Vulnerability
vendor_msrc·2022-02-08·CVSS 7.8
CVE-2022-21999 [HIGH] Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Components: Windows Print Spooler Components
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010351
Reference: https://support.microsoft.com/help/5010351
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010345
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5010342
Reference: https://support.microsoft.com/help/5010342
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB50103
GHSA
GHSA-88wr-wm4j-qgww: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-02-10·CVSS 7.8
CVE-2022-21997 [HIGH] CWE-269 GHSA-88wr-wm4j-qgww: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21999, CVE-2022-22717, CVE-2022-22718.
GHSA
GHSA-x6gv-8c9f-6r64: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-02-10·CVSS 7.1
CVE-2022-22717 [HIGH] CWE-269 GHSA-x6gv-8c9f-6r64: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22718.
GHSA
GHSA-r854-85qm-m3f9: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-02-10·CVSS 7.1
CVE-2022-22718 [HIGH] CWE-269 GHSA-r854-85qm-m3f9: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22717.
GHSA
GHSA-9cr3-63pg-942x: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-02-10·CVSS 7.1
CVE-2022-21999 [HIGH] CWE-22 GHSA-9cr3-63pg-942x: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-22717, CVE-2022-22718.
VulnCheck
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-21999 [HIGH] CWE-40 Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://asec.ahnlab.com/en/38156/; https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/; https://bi.zone/upload/for_download/Threat_Zone_2025_BI.ZONE_Research_rus.pdf; https://blog.qualys.com/vulnerabilities-threat-research/2025/05/08/inside-lockbit-defense-lessons-from-the-leaked-lockbit-negotiations; https://www.loginsoft.com/reports/annually/vulnera
No detection rules found.
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Tenable
Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
blogs_tenable·2024-03-12·CVSS 8.1
[HIGH] Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Privilege elevation exploits used in over 50% of insider attacks
blogs_bleepingcomputer·2023-12-08
Privilege elevation exploits used in over 50% of insider attacks
## Privilege elevation exploits used in over 50% of insider attacks
## Bill Toulas
Elevation of privilege flaws are the most common vulnerability leveraged by corporate insiders when conducting unauthorized activities on networks, whether for malicious purposes or by downloading risky tools in a dangerous manner.
A report by Crowdstrike based on data gathered between January 2021 and April 2023 shows that insider threats are on the rise and that using privilege escalation flaws is a significant component of unauthorized activity.
According to the report, 55% of insider threats logged by the company rely on privilege escalation exploits, while the remaining 45% unwittingly introduce risks by downloading or misusing offensive tools.
Rogue insiders typically turn against their employer b
Unit42
Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government
blogs_unit42·2023-09-22
Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government
Threat Research Center
Threat Research
Malware
## Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government
Lior Rochberger
Tom Fakterman
Robert Falcone
Published: September 22, 2023
Malware
Threat Research
Advanced Persistent Threat
Backdoor
China Chopper
CL-STA-0046
Gelsemium
Threat actors
Web shells
## Executive Summary
A cluster of threat actor activity that Unit 42 observed attacking a Southeast Asian government target could provide insight into a rarely seen, stealthy APT group known as Gelsemium.
We found this activity as part of an investigation into compromised environments within a Southeast Asian government. We identified the cluster as CL-STA-0046.
This unique cluster had activity spanning over six months
Unit42
Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government
blogs_unit42·2023-09-22
Rare Backdoors Suspected to be Tied to Gelsemium APT Found in Targeted Attack in Southeast Asian Government
## Executive Summary
A cluster of threat actor activity that Unit 42 observed attacking a Southeast Asian government target could provide insight into a rarely seen, stealthy APT group known as Gelsemium.
We found this activity as part of an investigation into compromised environments within a Southeast Asian government. We identified the cluster as CL-STA-0046.
This unique cluster had activity spanning over six months between 2022-2023. It featured a combination of rare tools and techniques that the threat actor leveraged to gain a clandestine foothold and collect intelligence from sensitive IIS servers belonging to a government entity in Southeast Asia.
In addition to an array of web shells, the main backdoors used by the threat actor were OwlProxy and SessionManager. This combinatio
Talos
Microsoft Patch Tuesday for Feb. 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-02-08·CVSS 7.8
CVE-2022-21997 [HIGH] Microsoft Patch Tuesday for Feb. 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 51 vulnerabilities across its large collection of hardware and software.
None of the vulnerabilities disclosed this month are considered “critical,” an extreme rarity for the company’s Patch Tuesdays. Additionally, none of the issues Microsoft patched have been exploited in the wild to this point, nor have they been publicly disclosed.
There are still a few vulnerabilities of note, however, including CVE-2022-21997, CVE-2022-21999 and CVE-2022-22715, which are all privilege elevation vulnerabilities in the Microsoft print spooler service. In the event an exploit is developed, an adversary could use these vulnerabilities to execute code as a system user or higher-level privileges.
There are four other similar vulnerabilit
Tenable
Microsoft’s February 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-21989)
blogs_tenable·2022-02-08·CVSS 7.8
[HIGH] Microsoft’s February 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-21989)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for Feb. 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-02-08·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Feb. 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Feb. 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 51 vulnerabilities across its large collection of hardware and software.
None of the vulnerabilities disclosed this month are considered “critical,” an extreme rarity for the company’s Patch Tuesdays. Additionally, none of the issues Microsoft patched have been exploited in the wild to this point, nor have they been publicly disclosed.
There are still a few vulnerabilities of note, however, including CVE-2022-21997 , CVE-2022-21999 and CVE-2022-22715 , which are all privilege elevation vulnerabilities in the Microsoft print spooler service. In the event an exploit is developed, an adversary could use these vulnerabilities to execute code
Crowdstrike
How Insiders Use Vulnerabilities Against Organizations
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How Insiders Use Vulnerabilities Against Organizations
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-02-09
Published
2022-03-25
Added to CISA KEV
Exploited in the wild