ZeroHour

CVE-2026-68848

mass

Heap Buffer Overflow in Windows Print Spooler Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-68848 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler Components. A local, authorized user with low privileges can trigger the flaw by interacting with the Print Spooler service, and no user interaction is required beyond the attacker's own local access. Successful exploitation allows the attacker to elevate privileges locally on the affected machine, with high impact on confidentiality, integrity, and availability (typically gaining rights well above the starting account). Any Windows system with the Print Spooler component present and running is affected; the spooler service is enabled by default on most Windows client and server editions, though the source data does not specify exact affected version ranges. As of now there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days.

What to do: Apply the Microsoft security update that addresses CVE-2026-68848 as part of regular patching, prioritizing shared print servers, multi-user systems, and endpoints where local users are untrusted. Where printing is not needed, disable the Print Spooler service (e.g., via Group Policy) or restrict it as a compensating mitigation, and verify spooler service status across your fleet. Given the low EPSS score and absence of known exploitation, routine patch-cycle remediation is reasonable, but re-check for updates if exploitation activity is reported.

Affected
Microsoft Windows (Print Spooler Components)
Estimated exposure
masshundreds of millions to over a billion Windows devices (Print Spooler runs by default on Windows client and most server editions) — The Print Spooler service is installed and enabled by default on essentially all Windows machines, and Microsoft's installed base of active Windows devices is on the order of 1.4 billion, so potential exposure is at the mass scale.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.