CVE-2026-69364
Windows Print Spooler Components Elevation of Privilege Vulnerability
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowThis is a Windows Print Spooler race-condition bug that can let an attacker with some access gain higher permissions; most small businesses should act by installing the Microsoft fixes for their Windows version.
CVE-2026-69364 is an elevation-of-privilege vulnerability in Windows Print Spooler components caused by a race condition (improper synchronization / concurrent execution) that can be triggered by an authorized attacker to gain higher privileges over a network; it is not listed in CISA KEV and no public exploit code is on record.
What to do now
- Check your exact Windows version and build (including Server editions) against the fixed versions listed below.
- If you are on an affected build, schedule and install the Microsoft update that brings your system to at least the corresponding fixed build.
- Re-check after updating that the OS build number matches one of the fixed versions for your specific Windows release.
- Prioritize systems that are reachable from the network and any machines that run printing services (Print Spooler).
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69364 and every CVE in our database. Create a free account — no credit card required.
Create Free Account