CVE-2026-85877: Windows Print Spooler Remote Code Execution Vulnerability
Published Sep 8, 2026
·Updated
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
Other sources
Windows Print Spooler Remote Code Execution Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Windows 11=24H2
10.0.26100.9445
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9445Patch KB5124008
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverity
Data Sourced
via NVD·06:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require attacker authentication or local access?
No prior privileges are required, and the attack vector is network-based. However, the CVSS vector indicates that user interaction is required.
2
Which systems are identified as affected?
The provided affected software entry identifies Microsoft Windows 11.