CVE-2026-32223
vulnerability analysis and mitigation

Overview

CVE-2026-32223 is a heap-based buffer overflow vulnerability in the Windows USB Print Driver that allows an unauthorized attacker to elevate privileges via a physical attack. It affects Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025, on both x64 and ARM64 architectures. The vulnerability was disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 6.8 (Medium), assigned by Microsoft (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) in the Windows USB Print Driver component. An attacker with physical access to a target system can insert a specially crafted malicious USB device, which triggers a buffer overflow condition in the driver without requiring any user interaction or prior privileges. The overflow corrupts heap memory in a manner that enables privilege escalation to administrator level. No public proof-of-concept code has been identified at this time, though a technical write-up and detection/mitigation scripts have been published (Microsoft MSRC, Vicarius vSociety).

Impact

Successful exploitation allows an attacker with physical access to escalate privileges to administrator level on the affected Windows system, resulting in high confidentiality, integrity, and availability impact. This enables complete system compromise, including unauthorized access to sensitive data, arbitrary system modification, and potential service disruption. Because physical access is required, the attack scope is limited to systems accessible to the attacker in person, reducing the risk of remote or large-scale exploitation (Microsoft MSRC, Feedly).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of this report. The EPSS score is approximately 0.058%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The physical attack vector significantly limits the exploitability compared to network-based vulnerabilities (Microsoft MSRC, Feedly).

Exploitation steps

  1. Physical Access: The attacker gains physical access to a target machine running a vulnerable version of Windows 11 (24H2, 25H2, or 26H1) or Windows Server 2025.
  2. Prepare Malicious USB Device: The attacker prepares a USB device with a crafted descriptor or firmware designed to trigger a heap-based buffer overflow in the Windows USB Print Driver upon connection.
  3. Insert USB Device: The attacker inserts the malicious USB device into an available USB port on the target system. No user interaction or authentication is required.
  4. Trigger Buffer Overflow: The Windows USB Print Driver processes the malicious USB device data, triggering a heap-based buffer overflow (CWE-122) that corrupts driver heap memory.
  5. Privilege Escalation: The memory corruption is leveraged to redirect execution flow or overwrite security-sensitive data structures, resulting in the attacker's process or code running with administrator-level privileges.
  6. Post-Exploitation: With elevated privileges, the attacker can install malware, exfiltrate data, modify system configurations, or establish persistence on the compromised system (Microsoft MSRC).

Indicators of compromise

  • Logs: Windows Event Logs showing unexpected privilege escalation events (Event ID 4672 – Special privileges assigned to new logon) shortly after a USB device connection event (Event ID 6416 – A new external device was recognized by the system).
  • Logs: System or application log entries referencing crashes or errors in the USB Print Driver (usbprint.sys) or related spooler components.
  • Network: Unusual outbound network connections from a system immediately following a USB device insertion event, potentially indicating post-exploitation activity.
  • File System: Unexpected new files, scheduled tasks, or services created under system or administrator context following a USB device connection.
  • Process: Unusual processes spawned with SYSTEM or administrator privileges that are not associated with normal user activity, particularly following USB device plug-in events.

Mitigation and workarounds

Microsoft released patches on April 14, 2026, addressing this vulnerability. Administrators should update to the following versions or later: Windows 11 24H2 → 10.0.26100.8246 (or 10.0.26100.32690 for Server 2025), Windows 11 25H2 → 10.0.26200.8246, Windows 11 26H1 → 10.0.28000.1836, and Windows Server 2025 → 10.0.26100.32690. As interim mitigations, organizations should implement strict physical access controls to prevent unauthorized USB device connections, consider disabling USB ports on systems that do not require USB functionality, and deploy endpoint detection and response (EDR) solutions to monitor for unusual privilege escalation activity. Detection and mitigation scripts are available via Vicarius vSociety (Microsoft MSRC, Vicarius vSociety).

Community reactions

The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by security vendors including Sophos and NSFOCUS, who highlighted it among multiple high-risk vulnerabilities patched that month (Sophos Blog, NSFOCUS). A technical write-up was published by researcher zeifan analyzing the Windows USB Print Driver null/overflow behavior (zeifan blog). Community discussion on social media (X/Twitter) noted the physical attack vector as a limiting factor for widespread exploitation risk.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management