Executive brief
A security vulnerability exists in the Windows Print Spooler, the service responsible for managing print jobs on Windows computers and servers. An authorized user on the network could exploit this flaw to run malicious code with high privileges on a target system. This could lead to a full system takeover, unauthorized data access, or disruption of business operations.
Technical details
A race condition (CWE-362) exists within the Windows Print Spooler Components due to improper synchronization when accessing shared resources. This flaw can lead to a use-after-free (CWE-416) condition. An attacker with low-privileged domain credentials can exploit this over the network without user interaction to achieve remote code execution (RCE). The vulnerability affects a wide range of Windows client and server versions, and Microsoft has released security updates to address the issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard and Server Core
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD
- 2026-07-14: advisory