Executive brief
A security vulnerability exists in the Windows USB Print Driver, which manages how the computer communicates with printers connected via USB. An attacker with physical access to a device could exploit this flaw to gain higher-level system permissions. This could allow them to bypass security restrictions, access sensitive data, or install malicious software on the machine.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Windows USB Print Driver. The vulnerability is triggered via a physical attack vector, where an unauthorized user with direct access to a USB port can provide specially crafted input to the driver. Successful exploitation allows the attacker to achieve local privilege escalation (LPE), gaining SYSTEM-level permissions on the host. The flaw affects multiple versions of Windows 11 and Windows Server 2025. Microsoft has released security updates to address this issue; users should ensure they are running the patched build versions specified in the vendor advisory.
Affected products
- Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.8246
- Microsoft Windows 11 25H2 up to (excluding) 10.0.26200.8246
- Microsoft Windows 11 26H1 up to (excluding) 10.0.28000.1836
- Microsoft Windows Server 2025 up to (excluding) 10.0.26100.32690
Timeline
- 2026-04-14: disclosed: Initial disclosure by Microsoft
- 2026-04-14: advisory: Microsoft MSRC advisory published
- 2026-05-26: other: NVD record updated with enrichment data and community scripts
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32223
- https://www.vicarius.io/vsociety/posts/cve-2026-32223-detection-script-heap-based-buffer-overflow-in-windows-usb-print-driver
- https://www.vicarius.io/vsociety/posts/cve-2026-32223-mitigation-script-heap-based-buffer-overflow-in-windows-usb-print-driver