Impact
The vulnerability is a use‑after‑free flaw in the Windows Print Spooler components that lets a user with local privileges obtain higher privileges on the system. The flaw crosses a memory safety boundary, allowing manipulation of privileged code paths. If successfully exploited, the attacker could run arbitrary code with system privileges, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Affected products are Microsoft Windows 10 starting from version 1607 through 22H2, Windows 11 from 23H2 through 26H1, and Windows Server releases 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations. All listed operating system releases that contain the Print Spooler services are vulnerable until the vendor publishes a fix. The specific build or servicing channel is not detailed in the CNA information, so all builds within the mentioned releases should be considered affected.
Risk and Exploitability
With a CVSS base score of 7, the flaw is considered medium severity. The EPSS score is not provided, but the lack of a KEV listing suggests that widespread exploitation is not currently documented. The attack vector is local; an attacker must already have some access to the target machine to invoke the use‑after‑free condition. While the exact exploitation steps are not disclosed, a typical vector would involve interacting with the Print Spooler service, for example by submitting a malicious print job or manipulating associated drivers. Because the flaw escalates privileges rather than arbitrarily executing code, defenses that limit local user rights can provide some mitigation but the most reliable approach is to apply the vendor supplied patch.
OpenCVE Enrichment