ZeroHour

CVE-2026-69309

mass

Double Free Local Privilege Escalation in Microsoft Windows Print Spooler

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69309 is a double free memory-corruption flaw (CWE-415) in the Windows Print Spooler components. An attacker who is already an authorized, low-privileged local user can trigger the double free, and due to the high attack complexity the conditions for successful exploitation must align precisely. A successful exploit elevates the attacker's privileges locally, with high impact on the confidentiality, integrity, and availability of the system. Any Windows system with the Print Spooler service running — the default state on most Windows clients and servers, especially multi-user machines such as terminal servers and print servers — is potentially affected. There is currently no known public proof-of-concept, no known exploitation in the wild, and the flaw is not in the CISA KEV catalog, with EPSS estimating only a 0.3% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's security update addressing CVE-2026-69309 as soon as it is available, prioritizing multi-user systems (terminal servers, jump hosts) and print servers where unprivileged users can log on. As an interim measure, stop or disable the Print Spooler service on systems that do not need printing or print-queue functionality, and restrict local logon rights on servers where the service must remain enabled. Since no public PoC or in-the-wild exploitation is known, monitoring for an updated Microsoft advisory and KEV additions is sufficient in the short term.

Affected
Microsoft Windows (Print Spooler Components)
Estimated exposure
masshundreds of millions of Windows endpoints and servers (Spooler service enabled by default) — The Print Spooler runs by default on essentially all Windows installations and Windows has over a billion active devices, so the potential install base is at the mass scale, though exploitation requires a local low-privileged user session.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.