Executive brief
Microsoft Standard XPS is a document-processing component that handles XPS (XML Paper Specification) files on Windows systems. A heap-based buffer overflow in this component allows an authenticated attacker to execute arbitrary code and elevate their privileges, potentially compromising system integrity and access to sensitive data across a network.
Technical details
A heap-based buffer overflow vulnerability exists in Microsoft Standard XPS that can be triggered when processing malformed XPS files. The vulnerability requires an authenticated attacker to supply a specially crafted XPS document. Exploitation allows arbitrary code execution with elevated privileges. The attack vector is network-based and requires prior authentication. Microsoft has issued a security patch to remediate this issue.
Affected products
- Microsoft Standard XPS
Timeline
- 2026-09-08: disclosed