CVE-2026-23669
8.8Microsoft · Windows Print Spooler
A use after free vulnerability in the Windows RPC Runtime allows an authorized attacker to execute arbitrary code over a network.
Executive summary
A critical use after free vulnerability in the Microsoft Windows RPC Runtime affects multiple versions of Windows and could allow an authenticated attacker to achieve remote code execution.
Vulnerability
The flaw exists within the RPC Runtime, where a use after free condition can be triggered by an authorized attacker to execute code remotely. The vulnerability requires the attacker to have at least low-level privileges to interact with the service.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain full control over the affected system, potentially leading to total system compromise, unauthorized access to sensitive data, and significant operational downtime. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational security, particularly in environments where print services are exposed to network-accessible user accounts.
Remediation
Immediate Action: Administrators must apply the latest security updates provided by Microsoft as detailed in the official update guide to patch the vulnerable RPC Runtime components.
Proactive Monitoring: Security teams should monitor network traffic for unusual RPC calls and review system access logs for unauthorized attempts to interact with the print spooler service.
Compensating Controls: Ensure that access to the Print Spooler service is restricted to authorized users and devices via network segmentation or Host-based Firewalls to limit the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution and the high severity of the CVSS score, organizations should prioritize patching affected Windows systems during the next maintenance cycle. Failure to remediate could allow attackers with valid user credentials to escalate privileges and compromise the integrity of the network environment.
More Microsoft CVEs
Sources
- RPC Runtime Library Remote Code Execution Vulnerability Vendor advisory