CVE-2026-32223Disclosure(microsoft / windows_11_24h2)

MEDIUMCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_11_24h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1
  • windows_server_2025

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-25); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2025

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-24: 1Mentions · 2026-04-25: 3Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-27: 1Exploit Tool / Code · 2026-04-27: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-27: 104-1504-1704-2404-2504-27
Signal classification2 categories
Disclosure
457.1%
PoC
342.9%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-151
PoC1
2026-04-171
Disclosure1
2026-04-241
Disclosure1
2026-04-253
Disclosure2PoC1
2026-04-271
PoC1
Full discourse7 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-32223: Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability https://t.co/jJaev33cGh

    Post summary

    The post announces the discovery of a new elevation‑of‑privilege vulnerability in Windows' USB printing stack, providing minimal technical details without any PoC, exploit, or mitigation information.

    368030114532.6K
    222.6K followersView on X
  • ENKI WhiteHat@ENKI_official_X
    PoC

    [1/2] CVE-2026-32223: heap overflow in usbprint.sys (IOCTL 0x220064). Malformed USB descriptor, Named Pipe spray + Ghost Chunk for kernel leak, forged IRP, SYSTEM. Writeup: https://www.enki.co.kr/en/media-center/blog/plug-me-if-you-can-exploiting-usb-printer-drivers-in-windows #CVE_2026_32223 #WindowsKernel #LPE #vulnresearch

    Post summary

    The post announces CVE‑2026‑32223, shares a writeup with a proof‑of‑concept, detailing exploitation techniques but does not mention active exploitation or patches.

    35801649010.8K
    390 followersView on X
  • nafiez@zeifan
    PoC

    I’ve successfully reproduced the CVE-2026-32223. If I get the opportunity, I’ll put together a detailed write-up. https://t.co/UXTGFjMk8m

    Post summary

    The author confirms having reproduced CVE‑2026‑32223 and intends to produce a write‑up, indicating a PoC has been developed, but no exploit tool, patch, technical details, or evidence of active exploitation is provided.

    12102197315.0K
    2.2K followersView on X
  • NullSecurityX@NullSecurityX
    Disclosure

    Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability CVE-2026-32223 http://youtube.com/@NullSecurityX https://t.co/YqVUt7DHFu

    Post summary

    The post announces an elevation‑of‑privilege vulnerability (CVE‑2026‑32223) in Windows USB printing stack, accompanied by generic links to a YouTube channel and a tweet.

    13201618411.2K
    12.3K followersView on X
  • PatchPoint.Official@_patchpoint_
    PoC

    We released a demo video(https://youtu.be/BXbc_WBIb74) for the CVE-2026-32223 Windows USB Printing Stack (usbprint.sys) Elevation of Privilege Vulnerability, patched by Microsoft in Apr 2026. Watch the video and subscribe to our private vulnerability PoC and detailed report service at http://Patchpoint.io.

    Post summary

    A demo video showcasing CVE-2026-32223 is released, offering a private PoC and detailed report, with Microsoft’s patch noted for April 2026.

    016046368.2K
    491 followersView on X
  • Outis@xfeylesof
    Disclosure

    CVE-2026-32223 USB printing stack #BıgBounty #CyberSecurity #windows

    Post summary

    A brief post announces CVE-2026-32223 as a vulnerability in Windows USB printing stack, but offers no further technical detail or evidence of exploitation.

    0000187
    1.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32223 Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. https://www.cve.org/CVERecord?id=CVE-2026-32223

    Post summary

    The post announces CVE‑2026‑32223, describing a heap-based buffer overflow that permits privilege escalation via a physical attack, without indicating PoC, exploit, or patch details.

    00000103
    57.2K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2025---

Explore more