ZeroHour

CVE-2026-70564

mass

Local Privilege Escalation via Heap Overflow in Windows Print Spooler

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-70564 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler components, rated High (7.8) under CVSS 3.1. It is triggered locally: an attacker who already holds low-privileged authorized access on a Windows machine can invoke spooler functionality with malformed input that overflows a heap buffer, with no user interaction required. Successful exploitation yields elevated (SYSTEM-level) privileges on that local machine, giving the attacker full control of the host. Any Windows system running the Print Spooler service — workstations and servers alike — is potentially in scope, per Microsoft's advisory. Exploitation status is currently quiet: there is no known public PoC, the flaw is not in CISA's KEV, and EPSS estimates only ~0.3% probability of exploitation in the next 30 days (25th percentile).

What to do: Apply the Microsoft security update that addresses CVE-2026-70564 as soon as it is available via Windows Update or the Microsoft advisory, and verify your hosts are on a patched build. As an interim mitigation, disable the Print Spooler service on systems that do not need printing (common on many servers), which removes the attack surface entirely. On shared or multi-user hosts, restrict local low-privilege sign-in to trusted accounts since exploitation requires local access.

Affected
Microsoft Windows Print Spooler Components
Estimated exposure
mass≈1 billion+ Windows devices (Print Spooler enabled by default on most Windows workstations and servers) — The Print Spooler service runs by default on standard Windows desktop and server SKUs and the global Windows install base is measured in the billions of devices, so the theoretical exposure surface is the entire Windows fleet, though only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.