Junglewise Threat Intelligence

CVE-2026-32223: Microsoft Windows USB Print Driver heap overflow privilege escalation

CVE-2026-32223 · Severity: medium · CVSS 6.8 · Published 2026-04-14

Technologies: Microsoft Windows 11 25h2, Microsoft Windows Server 2025, Microsoft Windows 11 24h2, Microsoft Windows 11 26h1, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows USB Print Driver, which manages how the computer communicates with printers connected via USB. An attacker with physical access to a device could exploit this flaw to gain higher-level system permissions. This could allow them to bypass security restrictions, access sensitive data, or install malicious software on the machine.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Windows USB Print Driver. The vulnerability is triggered via a physical attack vector, where an unauthorized user with direct access to a USB port can provide specially crafted input to the driver. Successful exploitation allows the attacker to achieve local privilege escalation (LPE), gaining SYSTEM-level permissions on the host. The flaw affects multiple versions of Windows 11 and Windows Server 2025. Microsoft has released security updates to address this issue; users should ensure they are running the patched build versions specified in the vendor advisory.

Affected products

  • Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.8246
  • Microsoft Windows 11 25H2 up to (excluding) 10.0.26200.8246
  • Microsoft Windows 11 26H1 up to (excluding) 10.0.28000.1836
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.32690

Timeline

  • 2026-04-14: disclosed: Initial disclosure by Microsoft
  • 2026-04-14: advisory: Microsoft MSRC advisory published
  • 2026-05-26: other: NVD record updated with enrichment data and community scripts

References

Related threats