Junglewise Threat Intelligence

CVE-2026-69376: Microsoft Standard XPS out-of-bounds read

CVE-2026-69376 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Standard XPS is a document format handler built into Windows. This vulnerability allows an authorized user to read memory outside intended boundaries, potentially exposing sensitive data from the system. An attacker with local access could exploit this to disclose information that would normally be protected.

Technical details

An out-of-bounds read vulnerability exists in Microsoft Standard XPS document parsing. The vulnerability requires an authorized attacker with local access to trigger the flaw, typically through opening a specially crafted XPS file. The out-of-bounds read can expose memory contents that may contain sensitive information. Attack vector is local and requires user or system interaction to process a malicious document. No network-based exploitation is possible.

Affected products

  • Microsoft Standard XPS

Timeline

  • 2026-09-08: disclosed

References

Related threats