Executive brief
The Windows Print Spooler is a core Windows service that manages printing tasks and handles communication with networked printers. A vulnerability in the Print Spooler allows an authorized attacker to crash the service remotely, disrupting printing functionality across an organization and potentially impacting document workflows and business operations.
Technical details
The vulnerability is a untrusted pointer dereference flaw in Windows Print Spooler components. The vulnerability requires authentication (the attacker must be an authorized user with network access to the Print Spooler), and allows the attacker to supply a malformed request that causes the service to dereference an untrusted pointer, leading to a denial of service condition (service crash). The attack vector is network-based. Microsoft has released or will release patches to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed