CVE-2026-69364
massRace Condition Privilege Escalation in Microsoft Windows Print Spooler
CVE-2026-69364 is a race condition (CWE-362) with an associated use-after-free weakness (CWE-416) in the Microsoft Windows Print Spooler components, caused by improper synchronization when concurrent operations access shared resources. It is triggered remotely when an authenticated, low-privileged user interacts with the spooler over the network in a way that lands inside a timing window; per the CVSS vector the attack has high complexity (AC:H) and requires user interaction (UI:R), making reliable exploitation difficult. A successful attacker elevates privileges on the targeted Windows host, with high impact to confidentiality, integrity and availability (CVSS 3.1 score 7.1, High). Any Windows system with the Print Spooler service enabled is potentially affected; the exact affected Windows versions are enumerated in Microsoft's advisory but are not specified in the available data. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
What to do: Install Microsoft's security update for CVE-2026-69364 via Windows Update/WSUS as soon as it is available, prioritizing print servers and multi-user hosts. Until patched, disable the Print Spooler service on systems that do not need printing (e.g., domain controllers and non-print servers) and restrict inbound network access to the spooler from untrusted users. Consult Microsoft's advisory for the definitive affected-version list and monitor for the emergence of public PoCs or KEV listing.
| Microsoft Windows Print Spooler Components | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.