CVE-2026-33101: Windows Print Spooler Elevation of Privilege Vulnerability
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
Other sources
Windows Print Spooler Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1836Patch KB5083768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8246Patch KB5083769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32690Patch KB5082063 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8246Patch KB5083769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2274Patch KB5082060
Event History
Frequently Asked Questions
Which systems are listed as affected?
Affected software includes Microsoft Windows 11, Windows 11 24H2, Windows 11 25H2, Windows 11 26H1, Windows Server 2025, Windows Server 2022, and Windows Server 2022 23H2 Edition.
What access does an attacker need to exploit this issue?
The attacker must already be authorized on the target system and able to attack it locally. No user interaction is required.
What could a successful exploit allow?
A successful exploit could enable elevation of privilege and has high potential impact on confidentiality, integrity, and availability.