CVE-2026-68835
massUse-After-Free Privilege Escalation in Windows Print Spooler
CVE-2026-68835 is a use-after-free memory corruption flaw (CWE-416) in Windows Print Spooler components. An attacker who already has low-privilege authorized access can trigger the flaw over the network; the CVSS vector indicates high attack complexity and user interaction, so reliable exploitation requires a favorable race condition. A successful attack yields high-impact compromise of confidentiality, integrity, and availability on the target, i.e., elevation of privileges beyond the attacker's authorized level. Any Windows system running the Print Spooler components is potentially affected, though the specific Windows versions in scope are defined in Microsoft's advisory rather than the summary data. Exploitation status is currently quiet: there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.5% probability of exploitation within 30 days (43rd percentile).
What to do: Apply Microsoft's current Windows security updates addressing this CVE as part of your next patch cycle, prioritizing hosts exposed to untrusted or low-privilege users. As a mitigation, disable the Print Spooler service on systems that do not need printing (most servers, jump hosts, and workstations without printers), consistent with standard Print Spooler hardening. No public PoC or in-the-wild exploitation is known, so re-check Microsoft's advisory and KEV status for updates on affected version ranges and exploit activity.
| Microsoft Windows Print Spooler Components | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.