Executive brief
Windows HTTP Print Provider contains a heap-based buffer overflow vulnerability that allows an authorized attacker to execute arbitrary code remotely over the network. This could lead to complete system compromise, allowing attackers to install malware, steal sensitive data, or disrupt print services across a network.
Technical details
A heap-based buffer overflow exists in the Windows HTTP Print Provider component due to improper bounds checking when processing network requests. An authenticated attacker on the network can craft malicious input to trigger the overflow and execute arbitrary code with the privileges of the Print Provider service. The vulnerability requires the attacker to be authorized to access the print service, but exploitation can be achieved remotely over the network. This allows arbitrary code execution in the context of the affected service, potentially leading to lateral movement and privilege escalation. A patch is available from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed