Impact
An out‑of‑bounds read in the Windows Print Spooler components lets an authorized local user read beyond the intended buffer boundary, exposing sensitive data that resides in the memory of the spooler process. The vulnerability does not allow elevation of privilege or remote code execution, but it permits leakage of confidential information if the user can write and read to the spooler service.
Affected Systems
The flaw affects multiple Windows releases, including Windows 10 version 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including server core installations). All common processor architectures are impacted: x86, x64, and arm64.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must already have local access and appropriate privileges to exploit the Print Spooler service; remote exploitation is not possible. Consequently, the risk level is moderate for systems where users have elevated rights to print services, and lower for minimal‑privilege environments.
OpenCVE Enrichment