Executive brief
Microsoft Standard XPS is a document format component used across Windows and Microsoft Office. A heap-based buffer overflow vulnerability allows an authorized attacker to execute arbitrary code or escalate privileges when processing specially crafted XPS files, potentially compromising system security and enabling further attacks.
Technical details
A heap-based buffer overflow exists in Microsoft Standard XPS component due to insufficient bounds checking during document parsing. The vulnerability requires an authorized user and network access to the affected system. An attacker can craft a malicious XPS file that, when processed, overwrites adjacent heap memory and achieves privilege escalation or arbitrary code execution. Patches are available through Microsoft Security Updates; users should apply them immediately.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed