Impact
A heap-based buffer overflow in the Microsoft Standard XPS rendering engine can be triggered by an authorized attacker, allowing the attacker to execute code with higher privileges on the affected system. The vulnerability combines an out‑of‑bounds write (CWE-122) with an integer overflow (CWE-190), leading to the escalation of privileges over a network.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including upcoming Server Core installations.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity for privilege escalation, while the EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting limited or unobserved exploitation to date. Based on the description, it is inferred that an authorized attacker—such as a user with local access or an authenticated service—could exploit this flaw by delivering malicious XPS content or by triggering the Standard XPS rendering in a privileged application. If successful, the privilege escalation could allow the attacker to gain full system access and potentially move laterally across the network.
OpenCVE Enrichment