{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2022-38028",
  "revision": 1,
  "title": "Windows print spooler — a constraints file run as the system",
  "summary": "An attacker modifies a constraints file that the Windows print spooler then executes with the machine's highest rights (SYSTEM). Microsoft publishes nothing about which file this is or how an ordinary user reaches it.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.8,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.14949,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-04-23",
    "prerequisites": "The attacker must already be able to run code as a local user."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1068"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Install the October 2022 Windows update, and stop the spooler service on machines that never print — that component has produced this class of flaw again and again.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2022-38028",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2022-38028",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2022-38028",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38028",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38028"
    },
    {
      "type": "vendor_advisory",
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-38028"
    }
  ],
  "published_at": "2022-10-11T19:15:15.067Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "microsoft",
    "windows",
    "print-spooler",
    "privilege-escalation",
    "kev"
  ]
}
