CVE-2022-29132
published 2022-05-10CVE-2022-29132: Windows Print Spooler Elevation of Privilege Vulnerability
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.67%
48.0th percentile
Windows Print Spooler Elevation of Privilege Vulnerability
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19297 | 10.0.10240.19297 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5125 | 10.0.14393.5125 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2928 | 10.0.17763.2928 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2274 | 10.0.18363.2274 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1706 | 10.0.19042.1706 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19043.1706 | 10.0.19043.1706 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.675 | 10.0.22000.675 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25954 | 6.1.7601.25954 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25954 | 6.1.7601.25954 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20371 | 6.3.9600.20371 |
| microsoft | windows_server | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25954 | 6.1.7601.25954 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21481 | 6.0.6003.21481 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23714 | 6.2.9200.23714 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20371 | 6.3.9600.20371 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77r6-c33j-gw48: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-19·CVSS 7.8
CVE-2022-30138 [HIGH] GHSA-77r6-c33j-gw48: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29104, CVE-2022-29132.
GHSA
GHSA-h63p-8q2p-crmm: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-11·CVSS 7.8
CVE-2022-29132 [HIGH] GHSA-h63p-8q2p-crmm: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29104.
GHSA
GHSA-mj9p-gcpr-r3x5: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-11·CVSS 7.8
CVE-2022-29104 [HIGH] GHSA-mj9p-gcpr-r3x5: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29132.
Microsoft
Windows Print Spooler Elevation of Privilege Vulnerability
vendor_msrc·2022-05-10·CVSS 7.8
CVE-2022-29132 [HIGH] Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Components: Windows Print Spooler Components
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013941
Reference: https://support.microsoft.com/help/5013941
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013945
Reference: https://support.microsoft.com/help/5013945
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5013942
Reference: https://support.microsoft.com/help/5013942
Reference: https://catalog.upd
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
blogs_tenable·2024-03-12·CVSS 8.1
[HIGH] Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
blogs_tenable·2023-01-10·CVSS 8.8
[HIGH] Microsoft’s January 2023 Patch Tuesday Addresses 98 CVEs (CVE-2023-21674)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s May 2022 Patch Tuesday Addresses 73 CVEs (CVE-2022-26925)
blogs_tenable·2022-05-10·CVSS 8.1
[HIGH] Microsoft’s May 2022 Patch Tuesday Addresses 73 CVEs (CVE-2022-26925)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-05-10·CVSS 8.1
[HIGH] Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
Microsoft returned to its normal monthly patching volume in May, disclosing and fixing 74 vulnerabilities as part of the company’s latest security update. This month’s Patch Tuesday includes seven critical vulnerabilities after Microsoft disclosed more than 140 security issues in April .
The point-to-point tunneling feature in Windows contains two of the most serious vulnerabilities that could allow an attacker to execute remote code on a targeted RAS server machine. While CVE-2022-21972 and CVE-2022-23270 are rated “critical,” Microsoft stated the attack complexity is high since an adversary needs to win a race condition, making it less likely an attacker could exploit these issues.
CVE-2022-26931 and C
Talos
Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-05-10·CVSS 8.1
CVE-2022-21972 [HIGH] Microsoft Patch Tuesday for May 2022 — Snort rules and prominent vulnerabilities
Microsoft returned to its normal monthly patching volume in May, disclosing and fixing 74 vulnerabilities as part of the company’s latest security update. This month’s Patch Tuesday includes seven critical vulnerabilities after Microsoft disclosed more than 140 security issues in April.
The point-to-point tunneling feature in Windows contains two of the most serious vulnerabilities that could allow an attacker to execute remote code on a targeted RAS server machine. While CVE-2022-21972 and CVE-2022-23270 are rated “critical,” Microsoft stated the attack complexity is high since an adversary needs to win a race condition, making it less likely an attacker could exploit these issues.
CVE-2022-26931 and CVE-2022-26923 are elevation of privilege vulnerabilities in Windows Kerberos and Windo
2022-05-10
Published