ZeroHour

CVE-2026-69364

mass

Race Condition Privilege Escalation in Microsoft Windows Print Spooler

CVSS 3.1
7.1 high
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-69364 is a race condition (CWE-362) with an associated use-after-free weakness (CWE-416) in the Microsoft Windows Print Spooler components, caused by improper synchronization when concurrent operations access shared resources. It is triggered remotely when an authenticated, low-privileged user interacts with the spooler over the network in a way that lands inside a timing window; per the CVSS vector the attack has high complexity (AC:H) and requires user interaction (UI:R), making reliable exploitation difficult. A successful attacker elevates privileges on the targeted Windows host, with high impact to confidentiality, integrity and availability (CVSS 3.1 score 7.1, High). Any Windows system with the Print Spooler service enabled is potentially affected; the exact affected Windows versions are enumerated in Microsoft's advisory but are not specified in the available data. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.5% probability of exploitation within 30 days.

What to do: Install Microsoft's security update for CVE-2026-69364 via Windows Update/WSUS as soon as it is available, prioritizing print servers and multi-user hosts. Until patched, disable the Print Spooler service on systems that do not need printing (e.g., domain controllers and non-print servers) and restrict inbound network access to the spooler from untrusted users. Consult Microsoft's advisory for the definitive affected-version list and monitor for the emergence of public PoCs or KEV listing.

Affected
Microsoft Windows Print Spooler Components
Estimated exposure
masshundreds of millions of Windows installations potentially affected (Print Spooler runs by default on Windows clients and print servers) — The Windows installed base exceeds one billion devices and the Print Spooler service is enabled by default on Windows workstations and print servers, so the plausibly affected population is on the order of hundreds of millions of systems,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.