CVE-2026-49166: Windows Print Configuration Elevation of Privilege Vulnerability
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
Other sources
Windows Print Configuration Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49166?
CVE-2026-49166 has a severity rating of 7.8, which is considered high.
How do I fix CVE-2026-49166?
The recommended fix for CVE-2026-49166 is to apply the available patch provided by Microsoft.
What type of vulnerability is CVE-2026-49166?
CVE-2026-49166 is classified as a Use After Free vulnerability in Microsoft Printer Drivers.
Who is affected by CVE-2026-49166?
CVE-2026-49166 affects users of Microsoft Windows 11 and Windows Server 2025.
What can an attacker do with CVE-2026-49166?
An authorized attacker can exploit CVE-2026-49166 to elevate their privileges on the affected system.