Executive brief
Microsoft Standard XPS is a file format used for document exchange and printing. An authorized attacker can read sensitive information from memory through a specially crafted XPS file, potentially exposing confidential data like passwords or personal information stored in the application's memory.
Technical details
The vulnerability is an out-of-bounds read in Microsoft Standard XPS, a file format parser. The flaw allows an authorized local attacker to read memory beyond allocated boundaries when processing a malicious XPS document. The attack requires user interaction (opening a crafted file) or local system access. An attacker can exploit this to disclose sensitive information resident in process memory. Patches are expected to be available through Microsoft's standard security update process.
Affected products
- Microsoft Standard XPS
Timeline
- 2026-09-08: disclosed