Junglewise Threat Intelligence

CVE-2026-69824: Microsoft Standard XPS integer underflow

CVE-2026-69824 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Microsoft Standard XPS is a document format handler used to process and display XML Paper Specification files. An integer underflow vulnerability in this component allows an attacker to execute arbitrary code on a system by sending a specially crafted XPS file, potentially leading to full system compromise without requiring user privileges or authentication.

Technical details

The vulnerability is an integer underflow (wraparound) condition in the Microsoft Standard XPS parser. The flaw exists in how the XPS handler processes specially crafted file structures, failing to validate numeric values that can wrap around and cause memory corruption. An attacker can exploit this by sending a malicious XPS file over the network to a vulnerable system; no user interaction or authentication is required if the XPS parser is accessible via network services. Successful exploitation results in arbitrary code execution with the privileges of the process handling the XPS file. A patch is available from Microsoft Security Response Center.

Affected products

  • Microsoft Standard XPS

Timeline

  • 2026-09-08: disclosed

References

Related threats