CVE-2026-69364 — Windows Print Spooler Components Elevation of Privilege

Summary A race condition in the Windows Print Spooler service leads to a use-after-free that allows an authenticated attacker to escalate privileges to SYSTEM. The vulnerability requires the attacker to win a race during spooler component processing, but successful exploitation grants full control of the affected system. Microsoft rates exploitation as More Likely on newer Windows versions. This vulnerability was discovered by Aretiq AI and responsibly disclosed to Microsoft, who addressed it in the September 2026 Patch Tuesday security updates. Microsoft has credited ECooper with Aretiq.AI for reporting this vulnerability in their security advisory. ...

September 8, 2026 · 2 min · Aretiq AI