CVE-2026-69364: Windows Print Spooler Components Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69364
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69364 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Windows Print Spooler
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-85877: Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker…nvd · 2026-09-08
- highCVE-2026-70564: Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker t…nvd · 2026-09-08
- highCVE-2026-69921: Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker t…nvd · 2026-09-08
- highCVE-2026-69838: Use after free in Windows Print Spooler Components allows an authorized attacker to elevate pr…nvd · 2026-09-08
- mediumCVE-2026-69569: Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacke…nvd · 2026-09-08
- mediumCVE-2026-69552: Generation of error message containing sensitive information in Windows Print Spooler Componen…nvd · 2026-09-08
More from Microsoft Security Response Center
- unknownCVE-2026-85062: Colord: Slow rejection of oversized malformed color strings2026-09-08
- mediumCVE-2026-18924: HTTP/2 server push UAF2026-09-08
- highCVE-2026-69630: Windows Win32k Elevation of Privilege Vulnerability2026-09-08
- mediumCVE-2026-80834: crypto: sun8i-ce - Remove crypto_rng interface2026-09-08
- unknownCVE-2026-83616: xmldom: Processing Instruction Target Injection Bypasses requireWellFormed2026-09-08