Junglewise Threat Intelligence

CVE-2026-33101: Microsoft Windows Print Spooler privilege escalation

CVE-2026-33101 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 25H2, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 11 Version 24H2, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows Print Spooler, the service responsible for managing print jobs on Windows computers and servers. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free vulnerability (CWE-416) exists within the Windows Print Spooler Components. The flaw is triggered when the service improperly handles objects in memory, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the system with low-level user privileges. Successful exploitation allows the attacker to execute code with elevated system privileges, potentially leading to a full compromise of the affected host. Microsoft has released security updates to address this issue across supported versions of Windows 11 and Windows Server.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 up to 10.0.26100.8246
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 up to 10.0.26200.8246
  • Microsoft Windows 11 version 26H1 10.0.28000.0 up to 10.0.28000.1836
  • Microsoft Windows Server 2022, 23H2 Edition 10.0.25398.0 up to 10.0.25398.2274
  • Microsoft Windows Server 2025 10.0.26100.0 up to 10.0.26100.32690

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References

Related threats