CVE-2022-21999 is a Windows Print Spooler elevation of privilege vulnerability. It is associated with the publicly referenced SpoolFool exploit and affects the Windows Print Spooler service. Successful exploitation allows a local attacker to abuse the vulnerable spooler behavior to elevate privileges on the host. Public references and offensive tooling indicate the flaw was used as a local privilege-escalation mechanism after initial access, including attempts to create a local administrator account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module implementing a local privilege escalation exploit for CVE-2022-21999 (SpoolFool) on Windows systems. The exploit abuses the Print Spooler's ability to set the SpoolDirectory to a user-writable location and leverages a directory junction to redirect the spool directory to a protected system path. By writing a malicious DLL to 'C:\Windows\System32\spool\drivers\x64\4' and manipulating the 'SetPrinterDataEx' registry key, the exploit causes the Print Spooler to load and execute the DLL as SYSTEM, granting the attacker full system privileges. The module is operational and provides a Meterpreter shell or custom payload execution as SYSTEM. The code is written in Ruby and is designed to be used within the Metasploit framework. The main file is 'modules/exploits/windows/local/cve_2022_21999_spoolfool_privesc.rb', and it contains all logic for checking vulnerability, setting up the exploit environment, and executing the payload. The exploit targets Windows 10, Windows 11, and Windows Server 2022 systems with a vulnerable Print Spooler service.
This repository contains a full exploit for CVE-2022-21999 (SpoolFool), a Windows Print Spooler local privilege escalation vulnerability. The exploit is implemented in C# (SpoolFool) and C++ (AddUser DLL), with an additional PowerShell wrapper for ease of use. The main exploit (SpoolFool) manipulates the Print Spooler service to load a user-supplied DLL (such as AddUser.dll) as SYSTEM, allowing arbitrary code execution with elevated privileges. The provided AddUser.dll payload creates a new local administrator account (admin/Passw0rd!). The exploit leaves several artifacts, such as the created printer, driver directory, and the loaded DLL, which are not cleaned up automatically. The exploit is operational and can be used as-is for privilege escalation on vulnerable Windows systems. The repository is well-structured, with separate directories for the exploit logic (SpoolFool) and the payload DLL (AddUser).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Microsoft vulnerability that CISA KEV’s knownRansomwareCampaignUse field silently flipped to Known during 2025 (evidence of ransomware campaign use).
Unknown (referenced as a Windows local privilege escalation exploit module name in Metasploit; no technical description is included in the content).
An elevation of privilege vulnerability in the Windows Print Spooler component.
A Windows Print Spooler local elevation-of-privilege vulnerability that can be exploited to gain higher privileges (e.g., SYSTEM/admin) on a compromised host; in this incident it was leveraged via the SpoolFool GitHub PoC to try to create a local admin account.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.