ZeroHour

CVE-2026-69838

mass

Use-After-Free Local Privilege Escalation in Windows Print Spooler Components

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69838 is a use-after-free vulnerability (CWE-416) in the Windows Print Spooler Components, rated High severity (CVSS 3.1 base score 7.0). It is triggered by an authorized attacker who already has low-privileged access on a local machine; the high attack complexity (AC:H) indicates exploitation depends on specific timing or memory-layout conditions rather than straightforward input. Successful exploitation lets the attacker elevate privileges on the local system, giving them greater control of the host. Any Windows system with the Print Spooler service running — the default on Windows workstations and most servers — is potentially affected, though the source data does not enumerate specific Windows versions. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns a 0.3% probability of exploitation within 30 days (17th percentile).

What to do: Apply Microsoft's security update addressing CVE-2026-69838 across Windows systems as it becomes available, prioritizing multi-user servers, jump hosts, and terminal servers where local users are less trusted. As an interim mitigation, consider disabling the Print Spooler service on systems that do not need printing, and restrict local sign-in rights on sensitive hosts since exploitation requires an authorized local user. Continue monitoring KEV and EPSS, as Windows Print Spooler flaws have historically attracted rapid follow-on exploitation.

Affected
Microsoft Windows Print Spooler Components
Estimated exposure
mass≈1 billion+ Windows installations (Print Spooler service enabled by default on Windows) — The Print Spooler runs by default on Windows client and server installations, and Microsoft has publicly reported over 1.4 billion monthly active Windows devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.