CVE-2022-21999

HIGH(7.8)KEVRansomwareElevated Risk

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Description

CVE-2022-21999 is a privilege escalation vulnerability in the Microsoft Windows Print Spooler service that allows a local authenticated attacker to gain SYSTEM-level privileges. The flaw is part of a series of Print Spooler vulnerabilities and can be exploited to execute arbitrary code with the highest privileges on the system. With an EPSS score of 2.1% (89.5th percentile), this vulnerability has been actively targeted. CISA has added CVE-2022-21999 to the Known Exploited Vulnerabilities catalog.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
March 25, 2022
Due Date
April 15, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftwindows 10 1507< 10.0.10240.19204
microsoftwindows 10 1607< 10.0.14393.4946
microsoftwindows 10 1809< 10.0.17763.2565
microsoftwindows 10 1909< 10.0.18363.2094
microsoftwindows 10 20h2< 10.0.19042.1526
microsoftwindows 10 21h1< 10.0.19043.1526
microsoftwindows 10 21h2< 10.0.19044.1526
microsoftwindows 11 21h2< 10.0.22000.493
microsoftwindows 7-
microsoftwindows 8.1-
microsoftwindows rt 8.1-
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016< 10.0.14393.4946
microsoftwindows server 2019< 10.0.17763.2565
microsoftwindows server 2022< 10.0.20348.524
microsoftwindows server 20h2< 10.0.19042.1526

References

Weakness Type

CWE-269: Improper Privilege Management

CVE-2022-21999 is caused by improper privilege management in the Windows Print Spooler service. The service fails to properly restrict certain operations available to low-privileged users, allowing an authenticated attacker to perform actions that escalate their privileges to SYSTEM level through the Print Spooler's elevated context.

Learn more: CWE-269 — Improper Privilege Management

Impact Analysis

CVE-2022-21999 has a CVSS v3.1 base score of 7.8 (High), reflecting the serious impact of local privilege escalation. While the attack requires local access and an authenticated user account, successful exploitation grants SYSTEM-level privileges, enabling complete control over the affected machine. The EPSS score of 2.1% (89.5th percentile) indicates significant exploitation activity. The Windows Print Spooler has been a recurring target for privilege escalation attacks, and CVE-2022-21999 follows the pattern established by PrintNightmare and related vulnerabilities. Organizations with exposed Print Spooler services face particular risk.

Exploit Maturity

CVE-2022-21999 has been actively exploited as a local privilege escalation vector. CISA confirmed exploitation by adding it to the KEV catalog. The vulnerability is part of the broader series of Print Spooler vulnerabilities that gained attention following PrintNightmare, with proof-of-concept exploits available publicly. The EPSS score of 2.1% (89.5th percentile) reflects ongoing exploitation activity by threat actors using it in post-exploitation scenarios.

Remediation

  1. Apply the February 2022 Windows security update that addresses CVE-2022-21999. Ensure all Windows systems are updated through Windows Update or WSUS.
  2. Disable the Print Spooler service on systems that do not require printing functionality, particularly on domain controllers and servers. Use Group Policy to disable the service across the organization where possible.
  3. Restrict Point and Print driver installation by configuring the RestrictDriverInstallationToAdministrators registry setting to prevent non-administrator users from installing printer drivers.
  4. Monitor for suspicious Print Spooler activity including unexpected DLL loading, unusual print job submissions, and anomalous process spawning from the spoolsv.exe process.
  5. Implement application control policies that restrict which DLLs can be loaded by the Print Spooler service, reducing the risk of exploitation through malicious driver packages.

Technical Details

CVE-2022-21999 is a privilege escalation vulnerability (CWE-269) in the Windows Print Spooler service (spoolsv.exe). The Print Spooler runs with SYSTEM privileges and manages print jobs and printer driver installations. The vulnerability exists because the service does not properly validate certain operations performed through the printer driver installation path, allowing an authenticated user to place malicious files in privileged locations or manipulate the driver loading process. By exploiting this weakness, a standard user can execute code in the context of the SYSTEM account. The attack builds on the well-documented Print Spooler attack surface that has produced numerous privilege escalation vulnerabilities, including the PrintNightmare series (CVE-2021-34527 and related CVEs).

Frequently Asked Questions

Is CVE-2022-21999 being actively exploited?

Yes, CISA confirmed active exploitation by including CVE-2022-21999 in the Known Exploited Vulnerabilities catalog. The vulnerability is used as a local privilege escalation step in attack chains. The EPSS score of 2.1% reflects significant exploitation activity.

What products are affected by CVE-2022-21999?

The Windows Print Spooler service across multiple versions of Microsoft Windows is affected, including Windows 10, Windows 11, and Windows Server versions with the Print Spooler service enabled.

How do I fix CVE-2022-21999?

Apply the February 2022 Windows security update. Disable the Print Spooler service on systems that do not require printing. Restrict printer driver installation to administrators only.

How severe is CVE-2022-21999?

CVE-2022-21999 has a CVSS v3.1 score of 7.8 (High) and enables local privilege escalation to SYSTEM level. It is part of the broader series of Print Spooler vulnerabilities and is actively used in post-exploitation attack chains.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score41.68%
EPSS Percentile98.6%

Dates

PublishedFebruary 9, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.