CVE-2026-23669Disclosure(microsoft / windows_10_1607)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-10); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-10: 3Mentions · 2026-03-11: 2Mentions · 2026-03-17: 1Mentions · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-03: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-17: 1Technical Details · 2026-04-03: 103-1003-1103-1704-03
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-103
Disclosure3
2026-03-112
General1Patch1
2026-03-171
General1
2026-04-031
Disclosure1
Full discourse7 posts
  • Andrea P@decoder_it
    Disclosure

    When you try to harden Windows PrintNotify callbacks, you end up exposing vulnerabilities in other protocols like EPMAP that have been sitting around (or even more) for 20 years https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23669

    Post summary

    The tweet points out that hardening Windows PrintNotify callbacks can expose legacy protocol vulnerabilities, citing CVE-2026-23669, but does not provide a PoC, exploit details, or patch information.

    014164305.3K
    9.2K followersView on X
  • Vicarius@vicariusltd
    Disclosure

    I've been wondering the same 🤔 ___ CVE of the Week CVE-2026-23669: High-Severity RCE in Windows Print Spooler This use-after-free (UAF) flaw present in the Windows Print Spooler service (spoolsv.exe) allows an authorized remote attacker with low-level privileges to execute arbitrary code with SYSTEM-level authority over a network. Exploiting this vulnerability could result in: - Complete System Takeover: Since the Print Spooler runs with high privileges, attackers can gain full control of the affected machine. - Network-Wide Compromise by Authenticated attackers that target Print Spooler services across the domain. Recommended actions: 1. Immediately install the latest Microsoft security updates for Windows 10, 11, and Windows Server 2019–2025. 2. Harden Remote RPC: Configure the RegisterSpoolerRemoteRpcEndPoint registry value to 2 to prevent the Print Spooler from accepting remote connections. If you cannot immediately apply patches, proceed to scripting measures to secure your infrastructure: Detection: https://www.vicarius.io/vsociety/posts/cve-2026-23669-detection-script-rce-vulnerability-in-windows-print-spooler Remediation: https://www.vicarius.io/vsociety/posts/cve-2026-23669-mitigation-script-rce-vulnerability-in-windows-print-spooler Let us know if you need help securing your systems or understanding these steps further! Thanks to @decoder_it for the research 🤝

    Post summary

    The post alerts readers to CVE-2026-23669, a high‑severity RCE in Windows Print Spooler, detailing its use‑after‑free nature, impact, and recommending Microsoft patches along with hardening steps and supporting detection/remediation scripts.

    10000360
    2.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Microsoft Windows (CVE-2026-23669) https://vuldb.com/?id.349988

    Post summary

    A severe vulnerability (CVE-2026-23669) in Microsoft Windows was disclosed, with a reference to its database entry on vuldb.com.

    0000175
    2.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-23669 Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-23669

    Post summary

    The text briefly discloses CVE-2026-23669 as a use‑after‑free flaw in Windows Print Spooler that permits remote code execution by an authorized attacker, but provides no evidence of exploitation or mitigation.

    00000158
    56.7K followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    Le spooler d'impression Windows permet encore l'exécution de code à distance en 2026. Use-after-free exploitable sur le réseau par tout utilisateur authentifié. Patch immédiat requis. #CVE-2026-23669 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23669

    Post summary

    Windows Print Spooler remains vulnerable to a network‑based remote code execution via a use‑after‑free flaw; a patch is immediately required as per Microsoft’s advisory.

    0000083
    13 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-23669 - Microsoft - Windows 10 Version 1607 - https://www.redpacketsecurity.com/cve-alert-cve-2026-23669-microsoft-windows-10-version-1607/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-23669 #microsoft #windows-10-version-1607

    Post summary

    The tweet merely cites a CVE alert with a link, providing no additional technical details, proof of concept, exploit code, or patch information.

    0000092
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-23669: HIGH] Use after free in Windows Print Spooler Components allows an authorized attacker to execute code over a network.#cve,CVE-2026-23669,#cybersecurity https://cvefind.com/CVE-2026-23669

    Post summary

    The statement releases a high‑severity use‑after‑free vulnerability in Windows Print Spooler, noting it enables authorized attackers to execute code over the network, but provides no exploit, patch, or evidence of active use.

    0000044
    601 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more