Executive brief
Windows PrintWorkflowUserSvc is a system component that handles print workflow operations on Windows systems. A use-after-free vulnerability allows an authorized attacker to execute arbitrary code and escalate privileges, potentially compromising system integrity and gaining full administrative access to affected machines.
Technical details
A use-after-free vulnerability exists in the Windows PrintWorkflowUserSvc component, allowing an authenticated attacker to trigger memory corruption by manipulating print workflow operations. The vulnerability requires an attacker to already have a foothold on the system (authorized user access). Exploitation enables privilege escalation from a standard user account to SYSTEM-level privileges. The attack vector is local/network-accessible to authenticated users. Microsoft has released security patches to address this vulnerability through its standard update channels.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed