ZeroHour

CVE-2026-68835

mass

Use-After-Free Privilege Escalation in Windows Print Spooler

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-68835 is a use-after-free memory corruption flaw (CWE-416) in Windows Print Spooler components. An attacker who already has low-privilege authorized access can trigger the flaw over the network; the CVSS vector indicates high attack complexity and user interaction, so reliable exploitation requires a favorable race condition. A successful attack yields high-impact compromise of confidentiality, integrity, and availability on the target, i.e., elevation of privileges beyond the attacker's authorized level. Any Windows system running the Print Spooler components is potentially affected, though the specific Windows versions in scope are defined in Microsoft's advisory rather than the summary data. Exploitation status is currently quiet: there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.5% probability of exploitation within 30 days (43rd percentile).

What to do: Apply Microsoft's current Windows security updates addressing this CVE as part of your next patch cycle, prioritizing hosts exposed to untrusted or low-privilege users. As a mitigation, disable the Print Spooler service on systems that do not need printing (most servers, jump hosts, and workstations without printers), consistent with standard Print Spooler hardening. No public PoC or in-the-wild exploitation is known, so re-check Microsoft's advisory and KEV status for updates on affected version ranges and exploit activity.

Affected
Microsoft Windows Print Spooler Components
Estimated exposure
masshundreds of millions of Windows endpoints and servers (Print Spooler enabled by default on most Windows systems) — The Print Spooler service ships enabled by default across the enormous Windows installed base of desktops and servers, so the pool of potentially affected systems is on the order of hundreds of millions, even though practical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.