Executive brief
Microsoft Standard XPS is a document processing component used to handle XPS (XML Paper Specification) files in Windows and associated applications. A heap-based buffer overflow in this component allows an authorized local attacker to execute arbitrary code with elevated privileges, potentially compromising system security and enabling further attacks.
Technical details
This vulnerability is a heap-based buffer overflow in the Microsoft Standard XPS component. The flaw allows an authorized local attacker to trigger a heap overflow condition, leading to privilege escalation. The attack requires local access and authorization; however, successful exploitation results in arbitrary code execution with elevated system privileges. A patch from Microsoft is expected to be available through their standard security updates.
Affected products
- Microsoft Standard XPS
Timeline
- 2026-09-08: disclosed