Impact
Concurrent execution using a shared resource within the Windows Print Spooler components creates a race condition due to improper synchronization, enabling an authorized attacker to gain elevated privileges. When the attacker’s credentials allow remote or local interaction with the Print Spooler service, the flaw can be triggered to override normal privilege boundaries and execute actions as a higher‑privileged user.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, while the EPSS score is not available, suggesting limited data on current exploitation activity. The vulnerability is not listed in the CISA KEV catalog, but its potential for privilege escalation over a network makes it a high‑risk threat for environments where the Print Spooler service is exposed to authorized users. The likely attack vector is a network‑based attack from a user who already has some level of access to the target system.
OpenCVE Enrichment