Impact
A flaw in Windows Print Spooler Components permits an authorized attacker to trigger an untrusted pointer dereference that causes the spooler to terminate unexpectedly, resulting in a denial‑of‑service condition. The vulnerability is classified as CWE‑822. An attacker who can send print jobs or otherwise interact with the spooler can exploit the flaw to halt printing services, impacting user productivity and potentially blocking other system services that depend on the spooler.
Affected Systems
Affected systems include multiple Windows 10 releases (1607 through 22H2) and Windows 11 releases (23H2 up to 26H1), as well as Windows Server editions 2012 through 2025, all of which run the Print Spooler service. The Microsoft update referenced by the advisory addresses the vulnerability across all listed editions, regardless of architecture.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate risk. No EPSS score is provided, and the vulnerability is not currently listed in the CISA KEV catalog. Because the attacker must be authorized to interact with the spooler, the attack vector is likely local or network delivery of a crafted print job. The exploitation requires only the ability to send data to the spooler; it does not necessitate privilege escalation, so any user with print permissions can potentially trigger the denial.
OpenCVE Enrichment