EXPOSURES › CVE-2022-38028
CVE-2022-38028
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.
This privilege escalation vulnerability enables attackers to gain SYSTEM-level access by modifying a JavaScript constraints file, posing a severe risk to DIB organizations relying on Windows systems for sensitive data. The vulnerability is actively exploited in the wild and is linked to ransomware campaigns, making it a critical compliance failure for FedRAMP vendors and hardware manufacturers shipping compromised Windows environments. DIB orgs must immediately patch affected systems and audit their print server configurations to prevent unauthorized access.
Shame score — Active exploitation in the wild with ransomware linkage and SYSTEM-level privilege escalation creates high embarrassment for vendors shipping unpatched Windows systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |