Junglewise Threat Intelligence

CVE-2026-69272: Microsoft Standard XPS heap buffer overflow

CVE-2026-69272 · Severity: high · CVSS 7.1 · Published 2026-09-08

Technologies: Microsoft Standard XPS. Vendors: Microsoft.

Executive brief

Microsoft Standard XPS is a document-processing component that handles XPS (XML Paper Specification) files on Windows systems. A heap-based buffer overflow in this component allows an authenticated attacker to execute arbitrary code and elevate their privileges, potentially compromising system integrity and access to sensitive data across a network.

Technical details

A heap-based buffer overflow vulnerability exists in Microsoft Standard XPS that can be triggered when processing malformed XPS files. The vulnerability requires an authenticated attacker to supply a specially crafted XPS document. Exploitation allows arbitrary code execution with elevated privileges. The attack vector is network-based and requires prior authentication. Microsoft has issued a security patch to remediate this issue.

Affected products

  • Microsoft Standard XPS

Timeline

  • 2026-09-08: disclosed

References

Related threats