CVE-2026-58608 Overview
CVE-2026-58608 is a race condition vulnerability in Windows Print Spooler Components that allows an authorized attacker to execute code over a network. The flaw stems from concurrent execution using a shared resource with improper synchronization [CWE-362]. An authenticated attacker who successfully wins the race condition can achieve remote code execution on affected Windows client and server systems. Microsoft rates the issue with a CVSS 3.1 base score of 7.5 (HIGH). The vulnerability affects a broad range of Windows 10, Windows 11, and Windows Server releases still in support.
Critical Impact
Successful exploitation grants remote code execution in the Print Spooler service context, exposing confidentiality, integrity, and availability of affected hosts.
Affected Products
- Microsoft Windows 10 (1607, 1809, 21H2, 22H2)
- Microsoft Windows 11 (24H2, 25H2, 26H1)
- Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025
Discovery Timeline
- 2026-07-14 - CVE-2026-58608 published to the National Vulnerability Database (NVD)
- 2026-07-20 - Last updated in NVD database
Technical Details for CVE-2026-58608
Vulnerability Analysis
The Windows Print Spooler service (spoolsv.exe) coordinates print jobs across local and networked printers. This vulnerability arises when multiple threads access shared spooler state without adequate synchronization primitives. An attacker who can trigger the racing code paths reliably can corrupt spooler state and steer execution into attacker-controlled memory.
Because Print Spooler runs with elevated privileges and exposes network-reachable interfaces, a successful race yields code execution with high impact on the host. The attack complexity is high, reflecting the timing precision required to win the race consistently.
Root Cause
The root cause is improper synchronization on a shared resource within Print Spooler Components. Concurrent operations on the same object create a Time-of-Check to Time-of-Use (TOCTOU) window. An attacker manipulating the object between check and use can violate assumed invariants, leading to memory corruption or logic errors that enable code execution.
Attack Vector
Exploitation requires network access and low-privileged authentication to the target. The attacker issues concurrent print-related operations designed to interleave in the vulnerable code path. No user interaction is required. The vulnerability is described in the Microsoft Security Update Guide. No public proof-of-concept code has been observed at the time of publication.
Detection Methods for CVE-2026-58608
Indicators of Compromise
- Unexpected child processes spawned by spoolsv.exe, particularly cmd.exe, powershell.exe, or rundll32.exe
- New or modified files under C:\Windows\System32\spool\drivers\ from remote or non-administrative sources
- Anomalous inbound SMB or RPC traffic targeting the Print Spooler service endpoint
- Repeated print job submissions from a single authenticated source within short time windows, consistent with race-condition brute-forcing
Detection Strategies
- Monitor process lineage for spoolsv.exe spawning shells, scripting engines, or LOLBins
- Alert on remote RPC calls to spooler interfaces (\pipe\spoolss) from unusual internal sources
- Correlate high-frequency, near-simultaneous print operations from the same principal, which can indicate race-window probing
Monitoring Recommendations
- Enable Windows Event Log auditing for the Microsoft-Windows-PrintService/Admin and Operational channels
- Forward endpoint and network telemetry into a centralized data lake for cross-host correlation
- Track spooler service crashes and restarts, which often precede or accompany race-condition exploitation attempts
How to Mitigate CVE-2026-58608
Immediate Actions Required
- Apply the Microsoft security update referenced in the Microsoft Security Update Guide to all affected Windows client and server systems
- Inventory hosts running the Print Spooler service and prioritize patching of domain controllers and servers exposing spooler interfaces to the network
- Restrict network access to Print Spooler RPC endpoints using host and perimeter firewalls
Patch Information
Microsoft addresses CVE-2026-58608 through its monthly security update channel. Consult the Microsoft Security Update Guide for the specific KB articles applicable to each affected Windows build. Deploy updates through Windows Update, WSUS, or Microsoft Endpoint Configuration Manager.
Workarounds
- Disable the Print Spooler service (Stop-Service Spooler; Set-Service Spooler -StartupType Disabled) on systems that do not require printing, especially domain controllers and servers
- Restrict inbound access to spooler RPC and SMB named pipes via Group Policy and Windows Firewall rules
- Limit accounts able to authenticate to spooler-exposed hosts, since exploitation requires valid credentials
# Disable Print Spooler on hosts that do not require printing
Stop-Service -Name Spooler -Force
Set-Service -Name Spooler -StartupType Disabled
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

