Impact
The flaw is a heap‑based buffer overflow in Windows Print Spooler Components that permits an authorised local user to elevate privileges to system or administrative levels. This type of local privilege escalation can compromise confidentiality, integrity, and availability of the affected machine. The vulnerability is classified as CWE‑122, reflecting a classic heap corruption scenario where an attacker can overwrite control data to execute arbitrary code from the context of the Print Spooler service.
Affected Systems
Affected products include Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from version 23H2 through 26H1, and Windows Server from 2012, 2012 R2, 2016, 2019, 2022, and 2025. The list reiterates the specific releases that were identified by the CNA as vulnerable.
Risk and Exploitability
With a CVSS score of 7.8 the risk is high, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating that widespread exploitation is currently unreported. The attack vector is local; an attacker must already have a legitimate local account or otherwise gain local access to trigger the buffer overflow in the Print Spooler service. Once executed, the attacker can gain elevated privileges on the host.
OpenCVE Enrichment