cbcvebase.
CVE-2022-38028
published 2022-10-11

CVE-2022-38028: Windows Print Spooler Elevation of Privilege Vulnerability

PriorityP181high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-05-14
Exploited in the wild
EPSS
14.95%
96.3th percentile
Windows Print Spooler Elevation of Privilege Vulnerability

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1950710.0.10240.19507
microsoftwindows_10_1607< 10.0.14393.542710.0.14393.5427
microsoftwindows_10_1809< 10.0.17763.353210.0.17763.3532
microsoftwindows_10_20h2< 10.0.19042.213010.0.19042.2130
microsoftwindows_10_21h1< 10.0.19043.213010.0.19043.2130
microsoftwindows_10_21h2< 10.0.19044.213010.0.19044.2130
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1950710.0.10240.19507
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.542710.0.14393.5427
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.353210.0.17763.3532
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.353210.0.17763.3532
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.213010.0.19042.2130
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.213010.0.19043.2130
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.213010.0.19044.2130
microsoftwindows_11_22h2< 10.0.22621.67410.0.22621.674
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.109810.0.22000.1098
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.67410.0.22621.674
microsoftwindows_8.1< 6.3.9600.206256.3.9600.20625
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.206256.3.9600.20625
microsoftwindows_rt_8.1< 6.3.9600.206256.3.9600.20625
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.239206.2.9200.23920
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.206256.3.9600.20625
microsoftwindows_server_2016< 10.0.14393.542710.0.14393.5427
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.542710.0.14393.5427
microsoftwindows_server_2019< 10.0.17763.353210.0.17763.3532

Detection & IOCsextracted from sources · hover to see the quote

filenameC:\ProgramData\servtask.bat
filenameC:\ProgramData\sam.save
filenameC:\ProgramData\security.save
filenameC:\ProgramData\system.save
filenameDefragmentSrv.exe
filenameDefragmentSrv.bat
filenamewayzgoose52.dll
pathC:\ProgramDataA\dobev3.80.15456
commandreg save hklm\sam C:\ProgramData\sam.save
  • Alert on files written to and executed from the root of C:\ProgramData — this is the custom detection signature that first identified the APT28 compromise.
  • Detect registry hive dumping (SAM, SECURITY, SYSTEM) via reg save commands writing to C:\ProgramData, followed by PowerShell Compress-Archive — indicative of GooseEgg/APT28 credential harvesting activity.
  • ·CVE-2022-38028 was patched by Microsoft in October 2022, but APT28 may have been exploiting it as a zero-day as far back as 2020 — patch status alone does not confirm absence of prior compromise.
  • ·GooseEgg can load other applications with SYSTEM-level permissions, enabling remote code execution and deployment of additional backdoors — treat any GooseEgg detection as a full system compromise requiring broad scope investigation.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.