CVE-2026-68848
massHeap Buffer Overflow in Windows Print Spooler Enables Local Privilege Escalation
CVE-2026-68848 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler Components. A local, authorized user with low privileges can trigger the flaw by interacting with the Print Spooler service, and no user interaction is required beyond the attacker's own local access. Successful exploitation allows the attacker to elevate privileges locally on the affected machine, with high impact on confidentiality, integrity, and availability (typically gaining rights well above the starting account). Any Windows system with the Print Spooler component present and running is affected; the spooler service is enabled by default on most Windows client and server editions, though the source data does not specify exact affected version ranges. As of now there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a low 0.2% probability of exploitation within 30 days.
What to do: Apply the Microsoft security update that addresses CVE-2026-68848 as part of regular patching, prioritizing shared print servers, multi-user systems, and endpoints where local users are untrusted. Where printing is not needed, disable the Print Spooler service (e.g., via Group Policy) or restrict it as a compensating mitigation, and verify spooler service status across your fleet. Given the low EPSS score and absence of known exploitation, routine patch-cycle remediation is reasonable, but re-check for updates if exploitation activity is reported.
| Microsoft Windows (Print Spooler Components) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.