Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Windows Print Spooler splwow64.exe Race Condition Local Privilege Escalation

IdentifiersCVE-2026-34342CWE-362· Concurrent Execution using Shared…

CVE-2026-34342 is a local elevation-of-privilege vulnerability in Windows Print Spooler Components. Available reporting indicates the flaw exists in the splwow64.exe process, part of the Windows Print Spooler service, and is caused by concurrent execution using a shared resource with improper synchronization. Supporting sources further describe the issue as unsafe use of shared memory leading to a race condition. A locally authenticated or otherwise authorized attacker who can execute low-privileged code on the target can attempt to win the race and trigger the flaw, resulting in privilege escalation on the affected Windows system.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows a local attacker to elevate privileges. Microsoft states exploitation can raise the attacker from a low integrity level to a medium integrity level. Supporting reporting also indicates this can enable arbitrary code execution in the context of the current user at the elevated integrity level. Microsoft’s CVSS assessment models high confidentiality, integrity, and availability impact, but the directly stated practical outcome in the provided content is local privilege escalation rather than remote code execution or SYSTEM-level compromise.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by limiting local code execution opportunities for untrusted users, restricting interactive logon and application execution on affected hosts, and minimizing use of accounts with local access that could be leveraged to trigger the flaw. Because exploitation is local and requires low privileges plus successful race timing, hardening workstation and server access paths and monitoring for suspicious abuse of Print Spooler-related processes may reduce risk. However, no vendor-specific workaround is provided in the supplied content, so patching is the primary mitigation.

Remediation

Patch, then assume compromise.

Microsoft has released an official security update for CVE-2026-34342 through the MSRC Security Update Guide. Remediation is to apply the vendor-provided update to affected Windows systems. No more specific product-version remediation detail is available in the provided content.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationWindowsoperating_system
Microsoft CorporationWindows 10 1607operating_system
Microsoft CorporationWindows 10 1809operating_system
Microsoft CorporationWindows 10 21h2operating_system
Microsoft CorporationWindows 10 22h2operating_system
Microsoft CorporationWindows 11 23h2operating_system
Microsoft CorporationWindows 11 24h2operating_system
Microsoft CorporationWindows 11 25h2operating_system
Microsoft CorporationWindows 11 26h1operating_system
Microsoft CorporationWindows Server 2012operating_system
Microsoft CorporationWindows Server 2012 R2operating_system
Microsoft CorporationWindows Server 2016operating_system
Microsoft CorporationWindows Server 2019operating_system
Microsoft CorporationWindows Server 2022operating_system
Microsoft CorporationWindows Server 2022 23h2operating_system
Microsoft CorporationWindows Server 2025operating_system
Microsoft CorporationWindows Server 23h2operating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.