Summary

A race condition in the Windows Print Spooler service leads to a use-after-free that allows an authenticated attacker to escalate privileges to SYSTEM. The vulnerability requires the attacker to win a race during spooler component processing, but successful exploitation grants full control of the affected system.

Microsoft rates exploitation as More Likely on newer Windows versions.

This vulnerability was discovered by Aretiq AI and responsibly disclosed to Microsoft, who addressed it in the September 2026 Patch Tuesday security updates. Microsoft has credited ECooper with Aretiq.AI for reporting this vulnerability in their security advisory.

Affected Versions

ProductBuildPatch
Windows 11 Version 26H1 (x64, ARM64)10.0.28000.2954KB5124012
Windows 11 Version 25H2 (x64, ARM64)10.0.26200.9445KB5124008
Windows 11 Version 24H2 (x64, ARM64)10.0.26100.9445KB5124008
Windows 11 Version 23H2 (x64, ARM64)10.0.22631.7582KB5122880
Windows 10 Version 22H2 (x64, ARM64, 32-bit)10.0.19045.7725KB5122878
Windows 10 Version 21H2 (x64, ARM64, 32-bit)10.0.19044.7725KB5122878
Windows 10 Version 1809 (x64, 32-bit)10.0.17763.9245KB5122876
Windows 10 Version 1607 (x64, 32-bit)10.0.14393.9512KB5123099
Windows Server 202510.0.26100.33438KB5122871
Windows Server 202210.0.20348.5622KB5122882
Windows Server 201910.0.17763.9245KB5122876
Windows Server 201610.0.14393.9512KB5123099
Windows Server 2012 R2 (ESU)6.3.9600.23397KB5123066
Windows Server 2012 (ESU)6.2.9200.26349KB5123065

Remediation

Apply the corresponding cumulative security update for your Windows version. Updates require a system restart.

Timeline

DateEvent
2026-05-23Vulnerability reported to Microsoft
2026-08-27Microsoft confirms vulnerability
2026-09-01Microsoft acknowledges patch release date
2026-09-08Microsoft releases security update (September 2026 Patch Tuesday)
2026-09-08Advisory published

References