Impact
A double free flaw in Windows Print Spooler components allows an attacker who already has local access to a system to raise their privileges. The vulnerability can provide the attacker with the ability to execute code or otherwise manipulate memory during spooler operations, which can lead to elevated rights across the machine. The impact is a local compromise that can enable full control of the affected system.
Affected Systems
Microsoft Windows 10 and Windows 11 clients—including releases 1607, 1809, 21H2, 22H2, 23H2, 24H2, 25H2, and 26H1—as well as Windows Server 2012 through 2025, including both full installations and Server Core editions are known to be affected.
Risk and Exploitability
The CVSS score of 7 indicates a moderate to high level of risk. No EPSS value is available, and the vulnerability is not currently listed in the CISA KEV catalog, implying limited known exploitation activity. The flaw requires local and authorized access to trigger, narrowing the attack surface to users who can run code on the target machine, but successfully exploiting it can grant complete system control. Prompt remediation is advised to prevent potential compromise.
OpenCVE Enrichment