CVE-2026-69769
massHeap-based buffer overflow RCE in Microsoft Windows HTTP Print Provider
CVE-2026-69769 is a heap-based buffer overflow (CWE-122) in the Windows HTTP Print Provider, the Windows component that handles printing over HTTP/IPP connections. According to the CVSS scoring, an unauthenticated attacker can trigger the flaw remotely over the network with no user interaction and low attack complexity, by sending crafted network traffic processed by the HTTP print component. Successful exploitation yields remote code execution on the affected host. Any Windows system running the HTTP Print Provider is potentially affected, so the population of potentially exposed systems spans Windows enterprise and consumer estates broadly; exact affected Windows versions are not specified in the available data and must be confirmed in Microsoft's advisory. There is currently no known public exploit or proof of concept, the flaw is not in CISA KEV, and EPSS assigns a modest 0.9% probability of exploitation within 30 days, though the critical 9.8 CVSS score warrants prompt patching.
What to do: Apply Microsoft's security update for CVE-2026-69769 via Windows Update as soon as it is available, and check the Microsoft advisory for the definitive list of affected Windows versions since this data contains none. As an interim measure, restrict or avoid HTTP/IPP-based printing (e.g., connecting to printers via http:// URLs) and harden or firewall hosts that act as print servers or regularly use IPP printing. Given the unauthenticated network vector and 9.8 severity, prioritize patching for internet-reachable and shared print infrastructure even though no exploitation is known yet.
| Microsoft Windows HTTP Print Provider | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.