Executive brief
Microsoft Standard XPS is a document viewing and processing component used to handle XPS (XML Paper Specification) files in Windows environments. A heap-based buffer overflow vulnerability allows an authenticated attacker to elevate their privileges across the network, potentially gaining unauthorized access to sensitive systems and data.
Technical details
This vulnerability is a heap-based buffer overflow in Microsoft Standard XPS that can be exploited by an authorized attacker to elevate privileges. The attack requires network reachability and valid authentication credentials. By triggering the buffer overflow through maliciously crafted XPS content, an attacker can overwrite heap memory and execute arbitrary code with elevated privileges. Patches are expected to be available through Microsoft's standard security update channels.
Affected products
- Microsoft Standard XPS
Timeline
- 2026-09-08: disclosed