CVE-2026-32223 is a heap-based buffer overflow vulnerability in the Windows USB Printing Stack, specifically the USB print driver component. Improper handling of data in usbprint.sys can lead to memory corruption on the heap. An attacker with physical access can trigger the flaw through the vulnerable USB printing path and leverage the resulting corruption to execute actions in a more privileged security context. The vulnerability is classified as an elevation of privilege issue and can result in compromise of the local system at SYSTEM level.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a standalone Windows local privilege escalation exploit for CVE-2026-32223 in usbprint.sys. Structure is minimal: README.md documents the bug and exploitation chain, usb-xpl.h defines IOCTL values, pool sizes, spray counts, fake IRP offsets, and Windows 11 25H2-specific kernel structure offsets, while usb-xpl.cpp implements the exploit logic. The exploit is not part of a larger framework. Core capability: it escalates from local userland to SYSTEM by abusing a heap-based buffer overflow in usbprint.sys during processing of USB printer string descriptors via IOCTL 0x220064 (Make1284IdStringFromUsbStrings per README). The code enumerates USB printer interfaces using the USBPRINT class GUID, filters for a crafted device whose instance ID contains VID_03F0&PID_1234, and opens the device handle. It then performs extensive kernel pool grooming using thousands of named pipes (spray, prefill, respray, ghost reclaim, fill, rewrite phases), aiming to create a controlled overlap/ghost chunk condition in NonPagedPoolNx. The exploit’s later stages use overlapped named-pipe queue entries and forged IRP-like structures to derive arbitrary kernel read/write primitives. Comments and constants indicate it leaks kernel addresses from queue structures, rewrites IRP/SystemBuffer-related fields, and triggers kernel memmove behavior through pipe I/O completion. The final privilege-escalation step explicitly references overwriting SeDebugPrivilege and then calling GetSystem(), after which the process remains alive holding handles. This is clearly exploit code rather than a detector: it contains active trigger logic, heap manipulation, kernel object corruption, and privilege-escalation steps. It is operational but environment-specific, depending on a malicious/emulated USB printer device and hardcoded kernel offsets for a particular Windows build.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.