Executive brief
Windows Print Spooler is a system service that manages print jobs on Windows computers. An authorized attacker with local access could exploit an out-of-bounds read vulnerability to access sensitive information stored in system memory, potentially exposing passwords, encryption keys, or other confidential data.
Technical details
The vulnerability is an out-of-bounds read in Windows Print Spooler Components that allows an authorized local attacker to disclose information. The attack requires local access and user privileges; remote exploitation is not possible. By reading memory outside intended bounds, an attacker can access sensitive data in adjacent memory regions. A patch is expected to be available through Microsoft's standard security update process.
Affected products
- Microsoft Windows Print Spooler <UNKNOWN>
Timeline
- 2026-09-08: disclosed