Heap-Based Buffer Overflow RCE in Windows Print Spooler Components (CVE-2026-85877)
AI analysis
CVE-2026-85877 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler components, fixed by Microsoft in its September 2026 Patch Tuesday release. A remote, unauthenticated attacker can trigger the flaw by sending crafted input to the Print Spooler service over the network, though the CVSS vector (UI:R) indicates some form of user interaction is required for successful exploitation. If exploited, the attacker gains arbitrary code execution on the target system, with the CVSS base metrics indicating high impact to confidentiality, integrity, and availability. Any Windows system with the Print Spooler service enabled is affected; the available data does not enumerate specific vulnerable Windows versions or builds. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation within the next 30 days (37th percentile).
What to do: Apply the September 2026 Microsoft Patch Tuesday security updates as soon as possible, prioritizing Windows servers and other systems where the Print Spooler is reachable from untrusted networks. As interim mitigation, disable the Print Spooler service on hosts that do not need printing and restrict inbound RPC/SMB access to spooler-enabled machines. Audit your estate for systems running the Print Spooler service and confirm patched status after deployment.
Affected
| Microsoft Windows Print Spooler Components (Windows systems with the Print Spooler service enabled) | — |
Estimated exposure
masshundreds of millions of Windows devices (Print Spooler enabled by default on Windows workstations and most servers) — The Print Spooler service is enabled by default on Windows client and server editions and the Windows installed base exceeds a billion endpoints, so the potentially exposed population is on the order of hundreds of millions of systems.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.