CVE-2026-69838
massUse-After-Free Local Privilege Escalation in Windows Print Spooler Components
CVE-2026-69838 is a use-after-free vulnerability (CWE-416) in the Windows Print Spooler Components, rated High severity (CVSS 3.1 base score 7.0). It is triggered by an authorized attacker who already has low-privileged access on a local machine; the high attack complexity (AC:H) indicates exploitation depends on specific timing or memory-layout conditions rather than straightforward input. Successful exploitation lets the attacker elevate privileges on the local system, giving them greater control of the host. Any Windows system with the Print Spooler service running — the default on Windows workstations and most servers — is potentially affected, though the source data does not enumerate specific Windows versions. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a 0.3% probability of exploitation within 30 days (17th percentile).
What to do: Apply Microsoft's security update addressing CVE-2026-69838 across Windows systems as it becomes available, prioritizing multi-user servers, jump hosts, and terminal servers where local users are less trusted. As an interim mitigation, consider disabling the Print Spooler service on systems that do not need printing, and restrict local sign-in rights on sensitive hosts since exploitation requires an authorized local user. Continue monitoring KEV and EPSS, as Windows Print Spooler flaws have historically attracted rapid follow-on exploitation.
| Microsoft Windows Print Spooler Components | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.