Junglewise Threat Intelligence

CVE-2026-34342: Microsoft Windows Print Spooler race condition privilege escalation

CVE-2026-34342 · Severity: high · CVSS 7 · Published 2026-05-12

Technologies: Microsoft Windows Print Spooler Components. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Print Spooler, the service responsible for managing print jobs on Microsoft Windows systems. An attacker who already has basic access to a computer could exploit a timing flaw to gain full administrative control over the device. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A race condition (CWE-362) exists within the Windows Print Spooler Components due to improper synchronization when handling shared resources. The vulnerability requires the attacker to have local access with low privileges (PR:L) and involves a high level of complexity (AC:H) to successfully time the exploit. If successful, the attacker can achieve elevated privileges, potentially reaching SYSTEM-level access, leading to a total compromise of confidentiality, integrity, and availability on the affected host. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Print Spooler Components

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References