Impact
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized local attacker to gain elevated privileges, potentially enabling execution of arbitrary code. The vulnerability is rated CVSS 7.8, indicating a high severity with significant impact on confidentiality, integrity, and availability for the affected system.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server-Core installations.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at this time. However, the attack vector requires local, authorized access, making it a concern for users with administrative rights. Exploitation leverages a heap overflow in the XPS rendering engine, a classic buffer overflow that can overwrite critical memory structures to elevate privileges.
OpenCVE Enrichment