CVE-2026-32223 is a heap-based buffer overflow vulnerability in the Windows USB Print Driver that could allow an attacker to escalate privileges through physical access to an affected system. The flaw exists in the driver's memory handling when processing USB print device communications. This vulnerability affects Windows systems running vulnerable versions of the USB Print Driver component. The vulnerability carries a CVSS score of 6.8 (Medium severity) with a physical attack vector, low complexity, and no authentication requirements. Exploitation could result in high-impact consequences across confidentiality, integrity, and availability. The physical attack requirement significantly constrains the practical threat landscape, as an attacker must have direct access to the targeted device. There is currently no evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and inactive status on the Hot List. The extremely low EPSS score of 0.00075 further suggests minimal real-world exploitation activity. However, the moderate FAUCET Risk Score of 45.0 indicates organizations should still prioritize patching this vulnerability as part of their standard security maintenance procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26200.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26200.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* | ||
< 10.0.28000.1836CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.