CVE-2022-41073
published 2022-11-09CVE-2022-41073: Windows Print Spooler Elevation of Privilege Vulnerability
PriorityP185high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-12-09
Exploited in the wild
EPSS
2.39%
82.1th percentile
Windows Print Spooler Elevation of Privilege Vulnerability
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_1607 | < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_1809 | < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_20h2 | < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_21h1 | < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_21h2 | < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_22h2 | < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11_21h2 | < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_22h2 | < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20671 | 6.3.9600.20671 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21768 | 6.0.6003.21768 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2022-41073 has been confirmed as actively exploited in the wild (Exploitation Detected) — prioritize detection of anomalous Print Spooler (spoolsv.exe) privilege escalation activity leading to SYSTEM-level access. ↗
- →Monitor Windows Print Spooler service (spoolsv.exe) for unexpected child processes or privilege escalation to SYSTEM, as successful exploitation grants full SYSTEM privileges. ↗
- →Track exploitation attempts against Windows Print Spooler Components as the affected component surface for CVE-2022-41073. ↗
- ·No public proof-of-concept or technical details have been disclosed by Microsoft; exploitation has been detected in the wild but the specific attack vector remains unspecified. ↗
- ·The vulnerability is described only as 'unspecified' in public sources, limiting the ability to craft precise behavioral detections beyond general Print Spooler privilege escalation patterns. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6xmp-59j9-c5x2: Windows Print Spooler Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-11-10
CVE-2022-41073 [HIGH] CWE-787 GHSA-6xmp-59j9-c5x2: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability.
VulnCheck
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-41073 [HIGH] CWE-787 Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Nov; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://community.riskiq.com/article/6dc6f62a; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_Report_2022.pdf
Remediation Due: 2022-12-09
Project0
Project Zero RCA: CVE-2022-41073: Windows Activation Contexts EoP
project_zero·CVSS 7.8
CVE-2022-41073 [HIGH] Project Zero RCA: CVE-2022-41073: Windows Activation Contexts EoP
# CVE-2022-41073: Windows Activation Contexts EoP
*Maddie Stone & James Forshaw*
## The Basics
**Disclosure or Patch Date:** November 08, 2022
**Product:** Windows
**Advisory:** https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41073
**Affected Versions:** pre-KB5019980 (Win 11), pre-KB5019959 (Win 10)
**First Patched Version:** KB5019980 (Win 11), KB5019959 (Win 10)
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Microsoft Threat Intelligence Center (MSTIC)
## The Code
**Proof-of-concept:** See exploit sample
**Exploit sample:** https://www.virustotal.com/gui/file/e8a94466e64fb5f84eea5d8d1ba64054a61abf66fdf85ac160a95b204b7b19f3/details
**Did you have access to the exploit sample when doing the analysis?** Yes
## The Vuln
CISA
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
cisa·2022-11-08·CVSS 7.8
CVE-2022-41073 [HIGH] CWE-787 Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41073; https://nvd.nist.gov/vuln/detail/CVE-2022-41073
Remediation Due Date: 2022-12-09
Microsoft
Windows Print Spooler Elevation of Privilege Vulnerability
vendor_msrc·2022-11-08·CVSS 7.8
CVE-2022-41073 [HIGH] Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Print Spooler Components: Windows Print Spooler Components
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5019966
Reference: https://support.microsoft.com/help/5019966
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5019959
Reference: https://support.microsoft.com/help/5019959
Reference: https://c
No detection rules found.
No public exploits indexed.
Securelist
A patched Windows attack surface is still exploitable
blogs_securelist·2024-03-14·CVSS 7.8
CVE-2022-22047 [HIGH] A patched Windows attack surface is still exploitable
Table of Contents
CSRSS | CVE-2022-22047
CSRSS | CVE-2022-37989
Print Spooler | CVE-2022-29104
Print Spooler | CVE-2022-41073
Windows Error Reporting | CVE-2023-36874
File History Service | CVE-2023-35359
Windows Error Reporting – 2nd exploit | CVE-2023-35359
BITS | CVE-2023-35359
How was the patch for this attack surface applied?
How to check if a vulnerability was exploited or any attempts were made to exploit it?
Authors
Elsayed Elrefaei
Ashraf Refaat
Kaspersky GERT
On August 8, 2023, Microsoft finally released a kernel patch for a class of vulnerabilities affecting Microsoft Windows since 2015 . The vulnerabilities lead to elevation of privilege (EoP), which allows an account with user rights to gain SYSTEM privileges on a vulnerable host. The root cause of this attack s
Securelist
A patched Windows attack surface is still exploitable
blogs_securelist·2024-03-14·CVSS 7.8
CVE-2022-22047 [HIGH] A patched Windows attack surface is still exploitable
Table of Contents
- CSRSS | CVE-2022-22047
- CSRSS | CVE-2022-37989
- Print Spooler | CVE-2022-29104
- Print Spooler | CVE-2022-41073
- Windows Error Reporting | CVE-2023-36874
- File History Service | CVE-2023-35359
- Windows Error Reporting – 2nd exploit | CVE-2023-35359
- BITS | CVE-2023-35359
- How was the patch for this attack surface applied?
- How to check if a vulnerability was exploited or any attempts were made to exploit it?
Authors
- Elsayed Elrefaei
- Ashraf Refaat
- Kaspersky GERT
On August 8, 2023, Microsoft finally released a kernel patch for a class of vulnerabilities affecting Microsoft Windows since 2015. The vulnerabilities lead to elevation of privilege (EoP), which allows an account with user rights to gain SYSTEM privileges on a vulnerable host. The root cause o
Tenable
Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
blogs_tenable·2024-03-12·CVSS 8.1
[HIGH] Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128 , a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the we
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128, a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the wea
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
## Table of Contents
Microsoft Patch Tuesday Summary
The November 2022 Microsoft Vulnerabilities are Classified as Follows:
OpenSSL 3.x Critical Vulnerability Highlights
OpenSSL 3.x Related Blogs and Resources
Microsoft Addressed Six Zero-Day Vulnerabilities
Microsoft Patch Tuesday Critical Vulnerability Highlights
Microsoft Release Summary
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response with Patch Management (PM)
Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Patch Tuesday Is
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
CVE-2022-41039
CVE-2022-41044
CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several v
Tenable
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
blogs_tenable·2022-11-08·CVSS 7.8
[HIGH] Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The November 2022 Microsoft Vulnerabilities are Classified as Follows:
- OpenSSL 3.x Critical Vulnerability Highlights
- OpenSSL 3.x Related Blogs and Resources
- Microsoft Addressed Six Zero-Day Vulnerabilities
- Microsoft Patch Tuesday Critical Vulnerability Highlights
- Microsoft Release Summary
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response with Patch Management (PM)
- Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
- Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
- CVE-2022-41039
- CVE-2022-41044
- CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several vulnerabilities for Windows PPTP were also disclosed.
Another notable vulnerability in
Crowdstrike
November 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41073http://packetstormsecurity.com/files/174528/Microsoft-Windows-Privilege-Escalation.htmlhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41073https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41073
2022-11-09
Published
2022-11-08
Added to CISA KEV
Exploited in the wild