Impact
A heap‑based buffer overflow exists in the Microsoft Standard XPS component, which is used to render XPS documents. If an attacker can supply malicious XPS input, the overflow corrupts adjacent memory and allows the execution of arbitrary code with the privileges of the user who created or processed the file. The result is an elevation of privileges to a higher level on the local system, potentially allowing the attacker to obtain administrative rights and compromise confidentiality, integrity, and availability of the affected machine.
Affected Systems
Affected products include Microsoft Windows 10 (versions 1607, 1809, 21H2 and 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and Microsoft Windows Server from 2012 up to 2025, including Server Core installations. The vulnerability resides in the Standard XPS component that is part of these operating systems.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, meaning publicly known exploits are not reported. The attack vector is local, requiring an authorized user or one who can create or edit XPS files to trigger the overflow. Successful exploitation results in local privilege escalation, enabling the attacker to gain higher-level permissions on the compromised system.
OpenCVE Enrichment