CVE-2026-69921
massHeap Overflow in Windows Print Spooler Enables Local Privilege Escalation
CVE-2026-69921 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Print Spooler components. An authorized local user can trigger it by causing the spooler service to process malformed input, overrunning a heap-allocated buffer without needing any user interaction. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 7.8). Any Windows system with the Print Spooler service running is affected, and because the service is enabled by default on most Windows clients and servers, the flaw touches a very broad installed base even though the attack requires low-privileged local access. As of this writing there is no public proof-of-concept, the CVE is not in the CISA KEV catalog, and EPSS estimates a 0.3% probability of exploitation within 30 days, indicating no confirmed in-the-wild exploitation yet.
What to do: Apply Microsoft's security update addressing CVE-2026-69921 to all Windows systems as soon as it is available, prioritizing workstations and multi-user servers where the Print Spooler is enabled. As an interim mitigation, stop and disable the Print Spooler service on hosts that do not need printing, such as domain controllers and dedicated application servers. Inventory which endpoints and servers have the spooler running and restrict local sign-in on those systems to trusted users until patches are in place.
| Microsoft Windows (Print Spooler Components) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.