Impact
An integer underflow in the Microsoft Standard XPS component lets a local attacker who has authorized access elevate privileges on the affected system. This flaw can grant the attacker higher level permissions than normally available, enabling further malicious activity on the compromised machine.
Affected Systems
Microsoft Windows 10 (Version 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (Versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025), including both full and Server Core installations, are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk for local privilege escalation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local, authorized user access; exploiting the integer underflow loop allows the user to gain elevated rights on the same machine. Given the lack of remote or network exposure, the exploitation probability is limited to environments where the attacker already has physical or logged‑in access.
OpenCVE Enrichment