Multiple vulnerabilities have been identified in Microsoft Windows, which could be exploited by remote or local attackers to disclose sensitive information or compromise a vulnerable system.
The first issue is caused by a buffer overflow error in the Windows Print Spooler when parsing certain printing data structures, which could be exploited by attackers to compromise a vulnerable system via a specially crafted RPC request and a malicious print server.
The second vulnerability is caused by an error in the Windows Printing Service that does not properly check the files that can be included with separator pages, which could allow authenticated attackers to read or print any file on an affected system.
The third vulnerability is caused by an error in the Windows Print Spooler that does not properly validate the paths from which a DLL may be loaded, which could allow authenticated attackers to load a malicious DLL and execute arbitrary code with SYSTEM privileges.