Junglewise Threat Intelligence

CVE-2026-68881: Microsoft Standard XPS out-of-bounds read

CVE-2026-68881 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Microsoft Standard XPS is a document format processor used by Windows systems. An authorized attacker with local access could read memory outside intended boundaries to disclose sensitive information on the system, potentially exposing user data or system credentials.

Technical details

This vulnerability is an out-of-bounds read in Microsoft Standard XPS, allowing an authorized local attacker to read sensitive information from memory. The vulnerability requires local access and authorization to trigger, reducing the attack surface compared to remote exploits. An attacker with these preconditions can disclose information stored in adjacent memory regions. No evidence of active exploitation in the wild has been reported. The CVSS score of 5.5 reflects the limited scope (local access required) and confidentiality impact (information disclosure).

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats