ZeroHour

CVE-2026-69921

mass

Heap Overflow in Windows Print Spooler Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-69921 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Print Spooler components. An authorized local user can trigger it by causing the spooler service to process malformed input, overrunning a heap-allocated buffer without needing any user interaction. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 7.8). Any Windows system with the Print Spooler service running is affected, and because the service is enabled by default on most Windows clients and servers, the flaw touches a very broad installed base even though the attack requires low-privileged local access. As of this writing there is no public proof-of-concept, the CVE is not in the CISA KEV catalog, and EPSS estimates a 0.3% probability of exploitation within 30 days, indicating no confirmed in-the-wild exploitation yet.

What to do: Apply Microsoft's security update addressing CVE-2026-69921 to all Windows systems as soon as it is available, prioritizing workstations and multi-user servers where the Print Spooler is enabled. As an interim mitigation, stop and disable the Print Spooler service on hosts that do not need printing, such as domain controllers and dedicated application servers. Inventory which endpoints and servers have the spooler running and restrict local sign-in on those systems to trusted users until patches are in place.

Affected
Microsoft Windows (Print Spooler Components)
Estimated exposure
mass≈1 billion+ Windows installations (spooler enabled by default on most Windows clients and servers) — The Print Spooler service runs by default on Windows, whose desktop and server installed base is on the order of a billion devices, though many hardened environments disable it on domain controllers and print-inactive servers, making the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.