Junglewise Threat Intelligence

CVE-2026-68885: Microsoft Standard XPS heap buffer overflow

CVE-2026-68885 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Standard XPS. Vendors: Microsoft.

Executive brief

Microsoft Standard XPS is a document processing component used in Windows systems to handle XPS (XML Paper Specification) files. A heap-based buffer overflow vulnerability allows an authorized local attacker to overflow memory and execute arbitrary code with elevated system privileges, potentially compromising the entire system.

Technical details

A heap-based buffer overflow exists in Microsoft Standard XPS, triggered during processing of malformed XPS documents. The vulnerability requires local access and authentication to the affected system. An attacker with these preconditions can craft a specially formatted XPS file that, when processed, causes a buffer overflow on the heap, enabling arbitrary code execution with elevated privileges. Microsoft has released patches addressing this vulnerability.

Affected products

  • Microsoft Standard XPS

Timeline

  • 2026-09-08: disclosed

References

Related threats