Junglewise Threat Intelligence

CVE-2026-50499: Microsoft Windows heap overflow in Print Spooler Components

CVE-2026-50499 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Print Spooler, the service responsible for managing print jobs on Microsoft Windows systems. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A heap-based buffer overflow (CWE-122) exists within the Windows Print Spooler Components. The vulnerability is triggered when the service improperly handles memory allocation for specific print-related data structures. An attacker with low-privileged local access can exploit this flaw without user interaction to execute arbitrary code with SYSTEM privileges. This is a local privilege escalation (LPE) vulnerability. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
  • 2026-07-14: advisory

References

Related threats