Description
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow within the Windows Print Spooler components permits an unauthorized attacker to execute code through a network connection. The flaw allows arbitrary code execution by exploiting memory corruption during spooler processing.

Affected Systems

Microsoft Windows 11 Version 24H2 is the affected product. No other vendors or products are listed as vulnerable.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is not available, so the current likelihood of exploitation is uncertain. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote over the network, targeting the Print Spooler service.

Generated by OpenCVE AI on September 9, 2026 at 03:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft cumulative update for Windows 11 24H2 that addresses the Print Spooler vulnerability.
  • If the Print Spooler service is not required, stop or disable the service to remove the attack surface.
  • Configure network firewall rules to restrict inbound access to the Print Spooler port to trusted hosts and monitor for unusual spooler activity.

Generated by OpenCVE AI on September 9, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
Title Windows Print Spooler Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:34:09.130Z

Reserved: 2026-09-04T18:18:19.325Z

Link: CVE-2026-85877

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:14.422Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:13.960

Modified: 2026-09-09T20:15:28.947

Link: CVE-2026-85877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:04:35Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow