Junglewise Threat Intelligence

CVE-2026-69367: Microsoft Standard XPS out-of-bounds read

CVE-2026-69367 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Standard XPS is a document format processor used to display and handle XPS (XML Paper Specification) files. An out-of-bounds memory read vulnerability allows an authorized local user to access sensitive information from the application's memory, potentially leading to the disclosure of confidential data.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Standard XPS that allows an authenticated attacker with local access to disclose information. The vulnerability requires authorization and local system access to exploit. An attacker can read memory outside the intended bounds of allocated data structures, potentially exposing sensitive information. This is a local information disclosure vulnerability with a CVSS score of 5.5 (medium severity).

Affected products

  • Microsoft Standard XPS

Timeline

  • 2026-09-08: disclosed

References

Related threats