Junglewise Threat Intelligence

CVE-2026-68897: Microsoft Standard XPS heap-based buffer overflow

CVE-2026-68897 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Standard XPS. Vendors: Microsoft.

Executive brief

Microsoft Standard XPS is a document processing component used to render and manage XPS (XML Paper Specification) files on Windows systems. A heap-based buffer overflow vulnerability allows an authorized local user to execute arbitrary code with elevated privileges, potentially compromising system integrity and enabling lateral movement within an organization.

Technical details

A heap-based buffer overflow exists in Microsoft Standard XPS, allowing an authenticated local attacker to corrupt heap memory and trigger privilege escalation. The vulnerability requires local access and authorization to trigger the vulnerable code path. Exploitation results in arbitrary code execution in the context of the affected process, potentially with elevated privileges. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Standard XPS

Timeline

  • 2026-09-08: disclosed

References

Related threats