ZeroHour

CVE-2026-69346

mass

Heap Buffer Overflow in Windows Print Spooler Enables Network Privilege Escalation

CVSS 3.1
8.0 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69346 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler components, assigned by Microsoft. An authorized attacker with low-level privileges on the network can trigger the overflow by sending crafted requests to the spooler; per the CVSS vector, low privileges and some user interaction are required for exploitation. Successful exploitation lets the attacker elevate privileges on the target system, with high impact on confidentiality, integrity, and availability. Any Windows installation running the Print Spooler components is potentially affected, with specific version ranges listed in Microsoft's advisory. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.7% probability of exploitation within 30 days.

What to do: Apply the security update for CVE-2026-69346 from Microsoft's advisory as a priority, since Print Spooler flaws have historically been a reliable privilege-escalation target. Until patching, audit which systems (especially servers) have the Print Spooler service running and disable it where printing is not required, and limit low-privileged users' network access to spooler endpoints. Check your patch-management and Microsoft advisory feeds for the exact affected version ranges, as they are not specified in the current data.

Affected
Microsoft Windows (Print Spooler Components)
Estimated exposure
masshundreds of millions to 1B+ Windows installations (Print Spooler is enabled by default on Windows clients and servers) — Windows runs on well over a billion devices and the Print Spooler service is enabled by default on most Windows clients and servers, though the practical at-risk population is smaller given the low-privilege and user-interaction…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.