Junglewise Threat Intelligence

CVE-2026-68891: Microsoft Standard XPS out-of-bounds read

CVE-2026-68891 · Severity: medium · CVSS 4.7 · Published 2026-09-08

Technologies: Microsoft Standard XPS. Vendors: Microsoft.

Executive brief

Microsoft Standard XPS is a document format handler used to process and display XML-based page specification files. An attacker with local system access could exploit an out-of-bounds read vulnerability to extract sensitive information from the application's memory, potentially exposing passwords, encryption keys, or other confidential data.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Standard XPS, a component that handles XPS document parsing and rendering. The flaw allows an authorized local attacker to read memory beyond intended buffer boundaries, potentially disclosing sensitive information. The attack requires local access and authorization to access the affected component. No evidence of active exploitation has been reported. Patches are available from Microsoft.

Affected products

  • Microsoft Standard XPS <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats