Impact
The CVE describes a double free flaw in Microsoft Printer Drivers that can be exercised by an attacker who already has local authorized privileges on a Windows system. Exploiting this defect allows the attacker to gain elevated privileges on the same host, potentially enabling the installation or configuration of printer drivers with higher authority than initially granted.
Affected Systems
Affected versions include Microsoft Windows 10 1607, 1809, 21H2, 22H2; Windows 11 24H2, 25H2, 26H1; and Microsoft Windows Server 2012, 2012 (Server Core), 2012 R2, 2012 R2 (Server Core), 2016, 2016 (Server Core), 2019, 2019 (Server Core), 2022, 2025, and 2025 (Server Core).
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. However, the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. It is not listed in CISA’s KEV catalog, implying no known widespread exploitation. The attack vector is local privilege escalation, requiring the attacker to be authorized to install or modify printer drivers on the target machine. The risk therefore applies only to users with the necessary local privileges and can be mitigated by patching the affected driver code.
OpenCVE Enrichment