ZeroHour

CVE-2026-69602

mass

Use-after-free in Windows PrintWorkflowUserSvc enables network privilege escalation

CVSS 3.1
7.1 high
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-69602 is a use-after-free (CWE-416) in the Windows Print Workflow User Service (PrintWorkflowUserSvc), a per-user component of the Windows print pipeline. According to Microsoft's description, an authorized (low-privileged) attacker can trigger the flaw over a network when the service mishandles an object during print workflow processing, freeing memory that is then reused; the CVSS vector indicates high attack complexity and user interaction are required. Successful exploitation allows the attacker to elevate privileges on the affected system, with high impact on confidentiality, integrity, and availability. Any Windows system running the Print Workflow service is affected; the provided data does not enumerate specific Windows releases, so defenders should consult Microsoft's advisory for the affected version list. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS of 0.6% (~45th percentile) suggests limited near-term exploitation risk.

What to do: Apply Microsoft's security update for CVE-2026-69602 via the current Windows cumulative update, prioritizing multi-user systems (RDS/VDI, shared hosts, print servers) where untrusted or low-privileged accounts can log in. Because the bug requires authentication and user interaction with high attack complexity, restricting interactive access to untrusted users and monitoring PrintWorkflowUserSvc errors/crashes limits interim risk. Verify affected Windows versions and applicable KBs against Microsoft's advisory, since the provided data does not list specific version ranges.

Affected
Microsoft Windows (PrintWorkflowUserSvc / Print Workflow User Service)
Estimated exposure
massHundreds of millions of Windows endpoints (component ships with the standard Windows print stack) — PrintWorkflowUserSvc is a built-in Windows client component, and the global Windows install base is on the order of hundreds of millions to over a billion devices, though exploitation additionally requires an authenticated user and user…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.