Impact
The vulnerability is an out‑of‑bounds read in Microsoft Standard XPS. An attacker who has local access and sufficient privileges can use this flaw to read memory beyond the intended buffer, potentially exposing sensitive data. This is an information disclosure flaw, specific to the XPS component of Windows, and does not result in code execution or denial of service.
Affected Systems
Affected products include multiple Windows 10 releases (1607, 1809, 21H2, 22H2), Windows 11 releases (23H2, 24H2, 25H2, 26H1), and all specified Windows Server releases from 2012 through 2025. Every listed version includes the Windows Standard XPS feature and is therefore vulnerable.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity for confidentiality impact, and the EPSS score is currently unavailable, so the likelihood of exploitation is uncertain. The issue is not listed in the CISA KEV catalog. The flaw can only be exploited locally by an authorized user or process, so exploitation requires presence on the target system but does not involve remote attack vectors.
OpenCVE Enrichment