Impact
A heap‑based buffer overflow exists in the Windows HTTP Print Provider that permits an authorized adversary with network access to execute arbitrary code. The flaw is an out‑of‑bounds write (CWE‑122) triggered by crafted traffic to the print service. This can lead to remote code execution, allowing the attacker to take full control of the affected system.
Affected Systems
The vulnerability covers a wide range of Microsoft Windows OS releases. It is present in Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 releases 23H2, 24H2, 25H2, and 26H1. All corresponding Windows Server editions from 2012 through 2025, including both standard and core installations, are affected. The issue spans 32‑bit, 64‑bit, and ARM64 platforms where the HTTP Print Provider is installed.
Risk and Exploitability
The CVSS base score of 8 denotes high severity. The EPSS score is reported as less than 1%, indicating a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, so large‑scale exploitation has not yet been documented. However, the flaw requires an attacker to have authorized network access to reach the print service, and once the buffer overflow is triggered the attacker can achieve full system compromise, making this a significant risk for any connected device running the affected Windows releases.
OpenCVE Enrichment