CVE-2022-38028Active Exploitation(microsoft / windows_10_1507)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Windows Print Spooler Elevation of Privilege Vulnerability

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-05-14. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_20h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_20h2windows_10_21h1windows_10_21h2windows_11_22h2windows_8.1windows_rt_8.1windows_server_2012

2 versions affected across 13 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-08: 1Mentions · 2026-05-15: 1Exploit Tool / Code · 2026-04-08: 1Active Exploitation · 2026-04-08: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 104-0805-15
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-081
Active Exploitation1
2026-05-151
General1
Full discourse2 posts
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text merely enumerates a long list of CVE identifiers with no additional context or technical information.

    10000106
    15 followersView on X
  • Yoko Hasebe (長谷部洋子 岩国市)@yokotf4yur
    Active Exploitation

    https://x.com/i/grok/share/e1780549889e429ab2a131fc5a30660fGooseEggツールの詳細技術解析です。GooseEggはAPT28(Forest Blizzard / Fancy Bear / GruesomeLarch)が独自開発したポストコンパイゼーションツール(post-compromise tool)で、CVE-2022-38028(Windows Print Spoolerの特権昇格脆弱性)を悪用してSYSTEM権限で任意の実行ファイル/DLLを起動するランチャーです。Microsoft Threat Intelligenceが2024年4月22日に詳細を公開し、VolexityのNearest Neighbor Campaign(2022年2月)でも同一ツールが確認されました。少なくとも2019年4月〜2020年6月から使用されており、2022年10月のMicrosoftパッチ適用後も過去の未パッチ環境で活用されています。1. 全体像と目的役割: 初期アクセス後(unprivilegedユーザー権限から)、Print Spoolerサービスを悪用してSYSTEM権限を取得し、任意のペイロード(バックドア、credential dumper、横移動ツールなど)をSYSTEMとして実行。 特徴: シンプルなランチャー(GooseEgg本体は「見せかけの実行」)。 **Living-off-the-Land(LoTL)**重視で、カスタムマルウェアを最小限に。 検知回避のため、DriverStore内の正当ドライバファイルを悪用し、シンボリックリンクを操作。 使用例(Nearest Neighbor): Wi-Fi近接侵入後、unprivileged RDPログイン → GooseEggで権限昇格 → SAM/NTDS.dit抽出 → Compress-ArchiveでZIP化。 2. 展開フロー(Batchスクリプト + GooseEgg本体)典型的な展開はバッチスクリプトから始まります(ファイル名例: execute.bat / doit.bat)。バッチスクリプトの動作:servtask.batを作成(レジストリハイブ保存+圧縮コマンドを記述)。 例(Microsoft報告より): reg save hklm\sam C:\ProgramData\http://sam.save reg save hklm\security C:\ProgramData\http://security.save reg save hklm\system C:\ProgramData\http://system.save GooseEgg実行ファイル(DefragmentSrv.exeなど)を呼び出し。 Scheduled Taskを作成してservtask.batをSYSTEMで定期実行(永続化)。 GooseEggバイナリ(DefragmentSrv.exe / justice.exeなど):コマンドライン引数で4種類のコマンドを受け取り、それぞれ異なるパスで実行。 本体は「見せかけ」だが、内部でPrint Spooler悪用ルーチンを実行。 成功確認のためwhoamiを実行し、SYSTEMであることを検証。 3. CVE-2022-38028悪用の核心メカニズム(技術的詳細)Microsoftが最も詳細に解析した部分です。Print SpoolerのJavaScript Constraintsファイル(プリンタドライバの制約JS)を悪用。ステップバイステップ:DriverStoreから正当ファイルをコピー:C:\Windows\System32\DriverStore\FileRepository\pnms009.inf_amd64_... などのドライバパッケージを、攻撃者制御ディレクトリ(C:\ProgramData\[ランダム]\v%u.%02u.%04u)にコピー。 対象JSファイル: MPDW-Constraints.js(Print-to-PDFドライバ関連)。 レジストリ操作(COMサーバー偽装):カスタムプロトコルハンドラを作成。 新しいCLSIDを登録(rogue COM server)。 オブジェクトマネージャー操作:C:ドライブのシンボリックリンクを攻撃者ディレクトリにリダイレクト(\??\C: を書き換え)。 Print Spoolerによる実行:Print SpoolerがC:\Windows\System32\DriverStore\...\MPDW-Constraints.jsをロードしようとする。 リダイレクトにより攻撃者制御のJSがロード → SYSTEM権限で実行。 結果: 埋め込み悪意DLL(wayzgooseXX.dll)がPrintSpoolerプロセス内でロード。 wayzgoose.dllの役割:基本的なランチャー(launcher application)。 コマンドラインで指定された任意のEXE/DLLをSYSTEM権限でspawn。 例: バックドアインストール、RCE、credential dumpingツール実行。 インストールディレクトリ例(Volexity/Microsoft共通):C:\ProgramData\[ランダム文字列]\v[バージョン].%02u.%04u(例: C:\ProgramData\Adobe\v3.80.15456 や dobev3.80.15456) ファイル構成例(Nearest Neighborで観測):http://DefragmentSrv.zip → 解凍でDefragmentSrv.exe + DefragmentSrv.bat wayzgoose52.dll(wayzgoose + 数字が特徴的) servtask.bat PDB: wayzgoose.pdb(デバッグ情報) 4. MITRE ATT&CK対応(主なTTPs)T1068 Exploitation for Privilege Escalation(CVE-2022-38028) T1543.003 Windows Service(Print Spooler悪用) T1053.005 Scheduled Task(永続化) T1562.004 Impair Defenses(Print Spooler経由) T1059.001 PowerShell / cmd.exe(servtask.bat内) 5. 検知・防御ポイントIoC:ファイル: DefragmentSrv.exe, wayzgoose*.dll, servtask.bat, http://DefragmentSrv.zip パス: C:\ProgramData\*\v*.*.* や MPDW-Constraints.js の異常配置 レジストリ: 新規CLSID / プロトコルハンドラ

    Post summary

    The analysis demonstrates that GooseEgg actively exploits CVE‑2022‑38028 in the wild, detailing the tool’s mechanisms, ongoing usage, and referencing Microsoft’s patch.

    1000057
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_20h2--arm64
OSmicrosoftwindows_10_20h2--x86
OSmicrosoftwindows_10_21h1---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more