{"id":"CVE-2026-32223","title":"Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.","summary":"Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"microsoft","product":"windows_11_24h2","affected":["windows_11_24h2 < 10.0.26100.8246","windows_11_25h2 < 10.0.26200.8246","windows_11_26h1 < 10.0.28000.1836","windows_server_2025 < 10.0.26100.32690"],"patched":["windows_11_24h2 10.0.26100.8246","windows_11_25h2 10.0.26200.8246","windows_11_26h1 10.0.28000.1836","windows_server_2025 10.0.26100.32690"],"published":"2026-04-14","updated":"2026-07-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-32223","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32223","label":"secure@microsoft.com"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-32223-detection-script-heap-based-buffer-overflow-in-windows-usb-print-driver","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-32223-mitigation-script-heap-based-buffer-overflow-in-windows-usb-print-driver","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.00522,"epssPercentile":0.43278,"ingestedAt":"2026-07-26T10:11:58.956Z","exploits":{"github":1,"githubRepos":["https://github.com/enki-kr/CVE-2026-32223-USBPrint-Exploit"],"checkedAt":"2026-09-23T07:13:58.729Z"},"exploitAvailable":true,"slug":"CVE-2026-32223","body":"## Overview\n\nHeap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.\n\n## Affected\n\n- `windows_11_24h2 < 10.0.26100.8246`\n- `windows_11_25h2 < 10.0.26200.8246`\n- `windows_11_26h1 < 10.0.28000.1836`\n- `windows_server_2025 < 10.0.26100.32690`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `windows_11_24h2 10.0.26100.8246`\n- `windows_11_25h2 10.0.26200.8246`\n- `windows_11_26h1 10.0.28000.1836`\n- `windows_server_2025 10.0.26100.32690`","depth":"twilight","depthScore":50,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5079,"id":"CVE-2026-32223","ts":1788887247940,"field":"exploit_available","old":"false","new":"true"},{"seq":3962,"id":"CVE-2026-32223","ts":1788886363575,"field":"exploit_available","old":"true","new":"false"},{"seq":2783,"id":"CVE-2026-32223","ts":1788883030284,"field":"exploit_available","old":"false","new":"true"},{"seq":1812,"id":"CVE-2026-32223","ts":1788882433197,"field":"exploit_available","old":"true","new":"false"},{"seq":916,"id":"CVE-2026-32223","ts":1788881866941,"field":"exploit_available","old":"false","new":"true"}]}