Microsoft published security advisories for a series of Windows PrintWorkflowUserSvc Elevation of Privilege vulnerabilities affecting the Windows printing workflow service. The issues were assigned multiple CVEs, including CVE-2024-49095, CVE-2025-21235, CVE-2025-55331, CVE-2025-55684, CVE-2025-55685, CVE-2025-55686, CVE-2025-55688, CVE-2025-55689, and CVE-2025-55691, indicating repeated security weaknesses in the same Windows component.
The advisories provide limited public detail, but each entry classifies the issue as an elevation of privilege flaw in PrintWorkflowUserSvc, a service tied to Windows print processing. For defenders, the cluster signals that organizations running Windows endpoints and print-enabled systems should prioritize Microsoft security updates covering this service, review exposure across workstation and server fleets, and monitor for post-compromise activity that could indicate local privilege escalation through the printing stack.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released Security Update Guide entries for CVE-2025-55331, CVE-2025-55684, CVE-2025-55685, CVE-2025-55686, CVE-2025-55688, CVE-2025-55689, and CVE-2025-55691, all described as Windows PrintWorkflowUserSvc elevation of privilege vulnerabilities. These entries represent a coordinated batch disclosure of multiple distinct flaws in the same Windows service.
Microsoft published a Security Update Guide entry for CVE-2025-21235, another elevation of privilege vulnerability affecting Windows PrintWorkflowUserSvc. The advisory marks a new distinct vulnerability disclosure in the same component.
Microsoft published a Security Update Guide entry for CVE-2024-49095, an elevation of privilege vulnerability in Windows PrintWorkflowUserSvc. This indicates the vulnerability was publicly disclosed and tracked by Microsoft on that date.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.