Impact
A heap‑based buffer overflow occurs within Microsoft Standard XPS processing, allowing a user who is already authenticated to the system to gain elevated rights. This flaw is a classic privilege‑escalation vulnerability (CWE‑122) that can compromise the integrity of the operating system without affecting external confidentiality.
Affected Systems
The vulnerability affects Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Core installations. This covers both desktop and server environments.
Risk and Exploitability
The CVSS score of 7.8 classifies it as a high‑severity local attack. Exploitation requires local access and an authorized user context, meaning an attacker must already have logged in or have some software running with the target's user rights. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. Nevertheless, the impact of privilege escalation warrants immediate attention.
OpenCVE Enrichment