Executive brief
Windows Print Spooler is a system component that manages print jobs and device communication across a network. A heap-based buffer overflow vulnerability allows an authorized user to execute arbitrary code with elevated system privileges, potentially compromising the entire machine and connected print infrastructure.
Technical details
A heap-based buffer overflow exists in Windows Print Spooler Components, triggered by processing malformed input. The vulnerability requires network reachability to the print spooler service and local or network authentication to trigger. An authorized attacker can overflow a heap buffer to corrupt memory and achieve privilege escalation, gaining SYSTEM-level access. The attack vector is network-based and affects Windows systems running vulnerable versions of the Print Spooler service. Microsoft has released security updates to patch this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed