Executive brief
Windows Print Spooler is a core service that manages print jobs on Windows systems. A heap-based buffer overflow vulnerability allows an authorized user with local access to execute code with elevated privileges, potentially gaining full control of the affected system.
Technical details
A heap-based buffer overflow exists in Windows Print Spooler Components. The vulnerability requires local access and authenticated user privileges to trigger. An attacker with these preconditions can overflow a heap buffer, allowing arbitrary code execution with elevated privileges. The CVSS score of 7.8 reflects the local attack vector and requirement for user authentication, though the potential impact is significant privilege escalation. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed