CVE-2026-69623
massHeap Buffer Overflow in Windows HTTP Print Provider Enables Network RCE
CVE-2026-69623 is a heap-based buffer overflow (CWE-122) in the Windows HTTP Print Provider, the built-in Windows component that handles HTTP-based (Internet Printing Protocol) print connections. A low-privileged authorized attacker can trigger the flaw over a network, and the CVSS 3.1 vector indicates user interaction is required, consistent with a victim connecting to an attacker-controlled or attacker-influenced printer or print resource. Successful exploitation yields code execution with high impact on confidentiality, integrity, and availability (score 8.0, High). Any supported Windows system where users or services connect to printers via HTTP/IPP is potentially affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV; EPSS estimates only about a 0.9% probability of exploitation in the next 30 days (58th percentile).
What to do: Apply Microsoft's security update for this CVE when it is released, and check the Microsoft advisory for the exact affected builds, since version details are not in the available data. Until patched, restrict HTTP/IPP printer connections to trusted print servers and consider blocking print traffic over HTTP/HTTPS to untrusted hosts for users who do not need web-based printing. Monitor endpoints where users add network printers for anomalous print-provider or spooler process activity.
| Microsoft Windows (HTTP Print Provider component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.