Impact
A Windows Print Spooler Components error message generation flaw allows an attacker with authorized access to reveal sensitive information via the network. The vulnerability is characterized by CWE‑209, which reflects disclosure of information through error handling. The impact is a confidentiality breach; no execution or denial of service capabilities are disclosed in the description.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server variants 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity, and the EPSS score is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a known actively exploited flaw. Exploitation requires an authorized attacker with the ability to interact with the Print Spooler service, likely over a network. The attack vector is inferred from the description that an attacker can trigger the sensitive error message; however, specific network stages are not detailed.
OpenCVE Enrichment