CVE-2026-69346
massHeap Buffer Overflow in Windows Print Spooler Enables Network Privilege Escalation
CVE-2026-69346 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler components, assigned by Microsoft. An authorized attacker with low-level privileges on the network can trigger the overflow by sending crafted requests to the spooler; per the CVSS vector, low privileges and some user interaction are required for exploitation. Successful exploitation lets the attacker elevate privileges on the target system, with high impact on confidentiality, integrity, and availability. Any Windows installation running the Print Spooler components is potentially affected, with specific version ranges listed in Microsoft's advisory. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.7% probability of exploitation within 30 days.
What to do: Apply the security update for CVE-2026-69346 from Microsoft's advisory as a priority, since Print Spooler flaws have historically been a reliable privilege-escalation target. Until patching, audit which systems (especially servers) have the Print Spooler service running and disable it where printing is not required, and limit low-privileged users' network access to spooler endpoints. Check your patch-management and Microsoft advisory feeds for the exact affected version ranges, as they are not specified in the current data.
| Microsoft Windows (Print Spooler Components) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.