Impact
A use‑after‑free flaw in the Windows Print Spooler components allows an attacker who can already authenticate to the system over a network to gain higher privileges. The flaw is a classic memory‑management error (CWE‑416) that allows an attacker to manipulate a freed object and execute privileged code. Successful exploitation would elevate an attacker’s rights, giving them the ability to install software, read or modify confidential data, or pivot within the network.
Affected Systems
The vulnerability affects multiple Microsoft Windows releases. On client operating systems it is present on Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 versions 23H2, 24H2, 25H2, 26H1, and 23H2 with arm64. On server editions it is found in Windows Server 2012 (both full and Server Core), 2012 R2 (full and Server Core), 2016, 2019 (full and Server Core), 2022, and 2025 (full and Server Core).
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity, and although the EPSS score is not available, the lack of listing in the CISA KEV catalog suggests no known widespread exploitation. The attack vector is inferred to be remote, requiring the attacker to be authenticated or have network access to the target, and to exploit the Print Spooler service’s memory. Once exploited, the attacker can lift privileges to system level, compromising confidentiality, integrity, and availability of the affected systems.
OpenCVE Enrichment