Executive brief
Windows Print Spooler is a critical system service that manages printer communication on Windows machines. A heap overflow vulnerability in this component allows an authorized local user to execute code with elevated privileges, potentially compromising the entire system and accessing sensitive data.
Technical details
A heap-based buffer overflow exists in the Windows Print Spooler Components. The vulnerability allows an authorized attacker with local access to trigger a memory corruption condition, leading to privilege escalation from a lower-privileged account to SYSTEM or Administrator level. Attack requires local authentication and user interaction is not required once access is established. An attacker can leverage this to execute arbitrary code with elevated privileges, bypassing security boundaries. A patch is available from Microsoft.
Affected products
- Microsoft Windows Print Spooler <UNKNOWN>
Timeline
- 2026-09-08: disclosed