Executive brief
Windows Print Spooler is a core Windows system component that manages printer jobs and communications. A race condition in the Print Spooler allows an authorized attacker to escalate privileges over a network, potentially gaining administrative access and full control over affected systems.
Technical details
This vulnerability is a race condition (CWE-362) in concurrent execution of shared resources within Windows Print Spooler components, caused by improper synchronization between threads. An authorized attacker with network connectivity can exploit this synchronization flaw to elevate privileges. The vulnerability allows an attacker to gain elevated permissions beyond their initial authorization level. Patches are available from Microsoft and should be applied promptly to affected systems.
Affected products
- Microsoft Windows Print Spooler <UNKNOWN>
Timeline
- 2026-09-08: disclosed