Executive brief
Microsoft Standard XPS is a document processing component used in Windows to render and handle XPS (XML Paper Specification) files. A heap-based buffer overflow in this component allows an authorized attacker to elevate their privileges on a system, potentially gaining administrative access over the network.
Technical details
This vulnerability is a heap-based buffer overflow in Microsoft Standard XPS, a document handling component. The vulnerability requires an authorized user on the system and can be exploited over a network. A successful exploit allows an attacker to elevate privileges, potentially obtaining SYSTEM-level access. The vulnerability is classified as a memory corruption issue in a core Windows component. A patch is expected to be available from Microsoft Security Response Center.
Affected products
- Microsoft Standard XPS <UNKNOWN>
Timeline
- 2026-09-08: disclosed