
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32223 is a heap-based buffer overflow vulnerability in the Windows USB Print Driver that allows an unauthorized attacker to elevate privileges via a physical attack. It affects Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025, on both x64 and ARM64 architectures. The vulnerability was disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 6.8 (Medium), assigned by Microsoft (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) in the Windows USB Print Driver component. An attacker with physical access to a target system can insert a specially crafted malicious USB device, which triggers a buffer overflow condition in the driver without requiring any user interaction or prior privileges. The overflow corrupts heap memory in a manner that enables privilege escalation to administrator level. No public proof-of-concept code has been identified at this time, though a technical write-up and detection/mitigation scripts have been published (Microsoft MSRC, Vicarius vSociety).
Successful exploitation allows an attacker with physical access to escalate privileges to administrator level on the affected Windows system, resulting in high confidentiality, integrity, and availability impact. This enables complete system compromise, including unauthorized access to sensitive data, arbitrary system modification, and potential service disruption. Because physical access is required, the attack scope is limited to systems accessible to the attacker in person, reducing the risk of remote or large-scale exploitation (Microsoft MSRC, Feedly).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of this report. The EPSS score is approximately 0.058%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The physical attack vector significantly limits the exploitability compared to network-based vulnerabilities (Microsoft MSRC, Feedly).
usbprint.sys) or related spooler components.Microsoft released patches on April 14, 2026, addressing this vulnerability. Administrators should update to the following versions or later: Windows 11 24H2 → 10.0.26100.8246 (or 10.0.26100.32690 for Server 2025), Windows 11 25H2 → 10.0.26200.8246, Windows 11 26H1 → 10.0.28000.1836, and Windows Server 2025 → 10.0.26100.32690. As interim mitigations, organizations should implement strict physical access controls to prevent unauthorized USB device connections, consider disabling USB ports on systems that do not require USB functionality, and deploy endpoint detection and response (EDR) solutions to monitor for unusual privilege escalation activity. Detection and mitigation scripts are available via Vicarius vSociety (Microsoft MSRC, Vicarius vSociety).
The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by security vendors including Sophos and NSFOCUS, who highlighted it among multiple high-risk vulnerabilities patched that month (Sophos Blog, NSFOCUS). A technical write-up was published by researcher zeifan analyzing the Windows USB Print Driver null/overflow behavior (zeifan blog). Community discussion on social media (X/Twitter) noted the physical attack vector as a limiting factor for widespread exploitation risk.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."