Impact
A heap-based buffer overflow exists in the Windows Print Spooler Components that can be exploited by an attacker who already has some level of authorized access to the target system. The flaw allows the attacker to overwrite portions of memory on the heap, enabling the execution of arbitrary code with the elevated permissions of the running process. The result is a privilege escalation that could give the attacker full control over the compromised machine.
Affected Systems
Affected Microsoft Windows operating systems include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025. All architectures listed in the CPE entries—x86, x64, arm64, and x64 server—are impacted.
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting it has not been widely exploited in the wild. Nonetheless, exploitation requires an attacker to have some level of authorized network access to the target machine, after which the memory corruption can occur via the Print Spooler service. The attack vector is network-based, and failure to remediate could allow an attacker to run unrestricted code with elevated privileges.
OpenCVE Enrichment