{"cveID":"CVE-2022-21999","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows Print Spooler Privilege Escalation Vulnerability","dateAdded":"2022-03-25","shortDescription":"Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-04-15","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2022-21999","cwes":["CWE-40","CWE-1386"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-21999","technique":"T1078","technique_name_at_mapping":"Valid Accounts","mapping_type":"exploitation_technique","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary who already has access to the victim system. This vulnerability, also known as SpoolFool, is a local privilege escalation vulnerability in the Windows Print Spooler service, which manages print operations on Windows systems. This vulnerability allows attackers to execute code with SYSTEM-level privileges by exploiting the `SpoolDirectory` configuration setting. The `SpoolDirectory` is writable by all users and can be manipulated using the `SetPrinterDataEx()` function, provided the attacker has `PRINTER_ACCESS_ADMINISTER` permissions.\n\nThe exploit involves creating a directory junction and using a Universal Naming Convention (UNC) path to write a malicious DLL to a privileged directory, such as `C:\\Windows\\System32\\spool\\drivers\\x64\\4`. This DLL is then loaded and executed by the Print Spooler service, granting the attacker elevated privileges. This method circumvents previous security checks designed to prevent privilege escalation through the Print Spooler.\n\nThe vulnerability has been exploited in the wild, with attackers using tools like the SpoolFool proof of concept (PoC) published on GitHub. One observed attack involved creating a local administrator account with a default password, indicating the potential for significant system compromise. The Gelsemium APT group has been linked to activity exploiting this vulnerability, highlighting its use in advanced persistent threat campaigns.","references":["https://www.logpoint.com/en/blog/a-spools-gold-cve-2022-21999-yet-another-windows-print-spooler-privilege-escalation-2/","https://www.rapid7.com/db/modules/exploit/windows/local/cve_2022_21999_spoolfool_privesc/","https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-21999","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary who already has access to the victim system. This vulnerability, also known as SpoolFool, is a local privilege escalation vulnerability in the Windows Print Spooler service, which manages print operations on Windows systems. This vulnerability allows attackers to execute code with SYSTEM-level privileges by exploiting the `SpoolDirectory` configuration setting. The `SpoolDirectory` is writable by all users and can be manipulated using the `SetPrinterDataEx()` function, provided the attacker has `PRINTER_ACCESS_ADMINISTER` permissions.\n\nThe exploit involves creating a directory junction and using a Universal Naming Convention (UNC) path to write a malicious DLL to a privileged directory, such as `C:\\Windows\\System32\\spool\\drivers\\x64\\4`. This DLL is then loaded and executed by the Print Spooler service, granting the attacker elevated privileges. This method circumvents previous security checks designed to prevent privilege escalation through the Print Spooler.\n\nThe vulnerability has been exploited in the wild, with attackers using tools like the SpoolFool proof of concept (PoC) published on GitHub. One observed attack involved creating a local administrator account with a default password, indicating the potential for significant system compromise. The Gelsemium APT group has been linked to activity exploiting this vulnerability, highlighting its use in advanced persistent threat campaigns.","references":["https://www.logpoint.com/en/blog/a-spools-gold-cve-2022-21999-yet-another-windows-print-spooler-privilege-escalation-2/","https://www.rapid7.com/db/modules/exploit/windows/local/cve_2022_21999_spoolfool_privesc/","https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-21999","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"primary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary who already has access to the victim system. This vulnerability, also known as SpoolFool, is a local privilege escalation vulnerability in the Windows Print Spooler service, which manages print operations on Windows systems. This vulnerability allows attackers to execute code with SYSTEM-level privileges by exploiting the `SpoolDirectory` configuration setting. The `SpoolDirectory` is writable by all users and can be manipulated using the `SetPrinterDataEx()` function, provided the attacker has `PRINTER_ACCESS_ADMINISTER` permissions.\n\nThe exploit involves creating a directory junction and using a Universal Naming Convention (UNC) path to write a malicious DLL to a privileged directory, such as `C:\\Windows\\System32\\spool\\drivers\\x64\\4`. This DLL is then loaded and executed by the Print Spooler service, granting the attacker elevated privileges. This method circumvents previous security checks designed to prevent privilege escalation through the Print Spooler.\n\nThe vulnerability has been exploited in the wild, with attackers using tools like the SpoolFool proof of concept (PoC) published on GitHub. One observed attack involved creating a local administrator account with a default password, indicating the potential for significant system compromise. The Gelsemium APT group has been linked to activity exploiting this vulnerability, highlighting its use in advanced persistent threat campaigns.","references":["https://www.logpoint.com/en/blog/a-spools-gold-cve-2022-21999-yet-another-windows-print-spooler-privilege-escalation-2/","https://www.rapid7.com/db/modules/exploit/windows/local/cve_2022_21999_spoolfool_privesc/","https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-21999","technique":"T1136.001","technique_name_at_mapping":"Local Account","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary who already has access to the victim system. This vulnerability, also known as SpoolFool, is a local privilege escalation vulnerability in the Windows Print Spooler service, which manages print operations on Windows systems. This vulnerability allows attackers to execute code with SYSTEM-level privileges by exploiting the `SpoolDirectory` configuration setting. The `SpoolDirectory` is writable by all users and can be manipulated using the `SetPrinterDataEx()` function, provided the attacker has `PRINTER_ACCESS_ADMINISTER` permissions.\n\nThe exploit involves creating a directory junction and using a Universal Naming Convention (UNC) path to write a malicious DLL to a privileged directory, such as `C:\\Windows\\System32\\spool\\drivers\\x64\\4`. This DLL is then loaded and executed by the Print Spooler service, granting the attacker elevated privileges. This method circumvents previous security checks designed to prevent privilege escalation through the Print Spooler.\n\nThe vulnerability has been exploited in the wild, with attackers using tools like the SpoolFool proof of concept (PoC) published on GitHub. One observed attack involved creating a local administrator account with a default password, indicating the potential for significant system compromise. The Gelsemium APT group has been linked to activity exploiting this vulnerability, highlighting its use in advanced persistent threat campaigns.","references":["https://www.logpoint.com/en/blog/a-spools-gold-cve-2022-21999-yet-another-windows-print-spooler-privilege-escalation-2/","https://www.rapid7.com/db/modules/exploit/windows/local/cve_2022_21999_spoolfool_privesc/","https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-21999","technique":"T1211","technique_name_at_mapping":"Exploitation for Defense Evasion","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"This vulnerability is exploited by an adversary who already has access to the victim system. This vulnerability, also known as SpoolFool, is a local privilege escalation vulnerability in the Windows Print Spooler service, which manages print operations on Windows systems. This vulnerability allows attackers to execute code with SYSTEM-level privileges by exploiting the `SpoolDirectory` configuration setting. The `SpoolDirectory` is writable by all users and can be manipulated using the `SetPrinterDataEx()` function, provided the attacker has `PRINTER_ACCESS_ADMINISTER` permissions.\n\nThe exploit involves creating a directory junction and using a Universal Naming Convention (UNC) path to write a malicious DLL to a privileged directory, such as `C:\\Windows\\System32\\spool\\drivers\\x64\\4`. This DLL is then loaded and executed by the Print Spooler service, granting the attacker elevated privileges. This method circumvents previous security checks designed to prevent privilege escalation through the Print Spooler.\n\nThe vulnerability has been exploited in the wild, with attackers using tools like the SpoolFool proof of concept (PoC) published on GitHub. One observed attack involved creating a local administrator account with a default password, indicating the potential for significant system compromise. The Gelsemium APT group has been linked to activity exploiting this vulnerability, highlighting its use in advanced persistent threat campaigns.","references":["https://www.logpoint.com/en/blog/a-spools-gold-cve-2022-21999-yet-another-windows-print-spooler-privilege-escalation-2/","https://www.rapid7.com/db/modules/exploit/windows/local/cve_2022_21999_spoolfool_privesc/","https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1078","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Valid Accounts","name_at_mapping":"Valid Accounts","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":56,"has_detection_strategy":true},{"id":"T1136.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Local Account","name_at_mapping":"Local Account","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":18,"has_detection_strategy":true},{"id":"T1211","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Stealth","name_at_mapping":"Exploitation for Defense Evasion","renamed":true,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":4,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}