Impact
The vulnerability is a heap-based buffer overflow in the Windows HTTP Print Provider that allows an attacker who can reach the target machine over the network to execute arbitrary code. This flaw is exploited without requiring local privileges, making the attack straightforward for an adversary who can contact the vulnerable service. If successfully exploited, the attacker achieves full control over the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10, versions 1607, 1809, 21H2, and 22H2; Windows 11, versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. The vulnerability impacts any installation that includes the Windows HTTP Print Provider component.
Risk and Exploitability
The flaw has a CVSS score of 9.8, indicating critical severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited public exploitation reports so far. However, the attack model is simple: an unauthorized remote attacker sends crafted input to the vulnerable provider, triggering the heap overflow and allowing arbitrary code execution without authentication. Because the flaw resides in a core Windows component, exploitation can occur on any affected OS version accessed over the network.
OpenCVE Enrichment