Executive brief
Windows Print Spooler is a core system service that manages print jobs and printer connections on Windows computers. An authorized attacker can trigger error messages that inadvertently expose sensitive information, which can be accessed over the network and used to support further attacks or system compromise.
Technical details
The vulnerability is an information disclosure flaw in Windows Print Spooler Components caused by improper sanitization of error messages. An attacker with local authorization (e.g., a domain user or service account) can craft requests that cause the Print Spooler service to generate error messages containing sensitive data such as file paths, configuration details, or authentication tokens. These error messages may be observable through network monitoring or log collection, allowing the attacker to gather reconnaissance data. The attack requires prior authorized access to the system. Patches are available from Microsoft.
Affected products
- Microsoft Windows Print Spooler
Timeline
- 2026-09-08: disclosed