ZeroHour

CVE-2026-69623

mass

Heap Buffer Overflow in Windows HTTP Print Provider Enables Network RCE

CVSS 3.1
8.0 high
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-69623 is a heap-based buffer overflow (CWE-122) in the Windows HTTP Print Provider, the built-in Windows component that handles HTTP-based (Internet Printing Protocol) print connections. A low-privileged authorized attacker can trigger the flaw over a network, and the CVSS 3.1 vector indicates user interaction is required, consistent with a victim connecting to an attacker-controlled or attacker-influenced printer or print resource. Successful exploitation yields code execution with high impact on confidentiality, integrity, and availability (score 8.0, High). Any supported Windows system where users or services connect to printers via HTTP/IPP is potentially affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV; EPSS estimates only about a 0.9% probability of exploitation in the next 30 days (58th percentile).

What to do: Apply Microsoft's security update for this CVE when it is released, and check the Microsoft advisory for the exact affected builds, since version details are not in the available data. Until patched, restrict HTTP/IPP printer connections to trusted print servers and consider blocking print traffic over HTTP/HTTPS to untrusted hosts for users who do not need web-based printing. Monitor endpoints where users add network printers for anomalous print-provider or spooler process activity.

Affected
Microsoft Windows (HTTP Print Provider component)
Estimated exposure
masspotentially hundreds of millions of Windows devices (HTTP Print Provider ships with the OS; ~1.4B Windows install base) — The HTTP Print Provider is a built-in Windows component and Windows runs on roughly 1.4 billion devices, though practically reachable exposure is narrower and limited to hosts where users or services connect to HTTP/IPP printers.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.