Skip to content
COOEY

EXPOSURES › CVE-2022-38028

CVE-2022-38028

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-04-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-38028 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildprivilege-escalationransomwareunpatched

Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.

This privilege escalation vulnerability enables attackers to gain SYSTEM-level access by modifying a JavaScript constraints file, posing a severe risk to DIB organizations relying on Windows systems for sensitive data. The vulnerability is actively exploited in the wild and is linked to ransomware campaigns, making it a critical compliance failure for FedRAMP vendors and hardware manufacturers shipping compromised Windows environments. DIB orgs must immediately patch affected systems and audit their print server configurations to prevent unauthorized access.

Shame score — Active exploitation in the wild with ransomware linkage and SYSTEM-level privilege escalation creates high embarrassment for vendors shipping unpatched Windows systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized