Executive brief
A security vulnerability has been identified in the printer drivers used by Microsoft Windows. This flaw allows an individual who already has basic access to a computer to gain full administrative control over the system. Such an exploit could lead to unauthorized software installation, data theft, or complete disruption of the affected server or workstation.
Technical details
A use-after-free (CWE-416) vulnerability exists within the Microsoft Printer Driver component. The flaw is triggered when the system attempts to use a memory pointer after it has been freed, leading to memory corruption. An attacker with low-privileged local access can exploit this condition to execute arbitrary code with elevated system privileges. The vulnerability affects multiple versions of Windows 11 and Windows Server 2025. Microsoft has released security updates to address this issue by improving memory management within the driver stack.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory