Impact
A heap based buffer overflow exists in Microsoft Standard XPS that allows an authorized attacker to elevate privileges over a network. The flaw originates when an attacker can supply a specially crafted XPS payload that overflows a heap buffer, enabling them to execute code with higher privilege levels. The weakness corresponds to CWE‑122 and can compromise confidentiality, integrity, and availability by allowing the attacker to gain full control of the affected system.
Affected Systems
Affected are Microsoft Windows 10 build 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 releases 23H2, 24H2, 25H2 and 26H1 across x86, x64 and ARM architectures; and Microsoft Windows Server 2012 (both standard and Server Core), 2012 R2, 2016, 2019, 2022 and 2025. The version information is tied to the build periods listed, and all architecture variants listed in the CPE entries are impacted.
Risk and Exploitability
The CVSS score of 8 indicates a high severity. Although the EPSS score is not available, the lack of listing in the CISA KEV catalog suggests no confirmed exploitation yet, but the vulnerability still poses a significant risk. Based on the description, the attack vector is likely remote over a network where the attacker can send a malicious XPS file or interact with the XPS driver from a remote session. An attacker with local user privileges could trigger the overflow by printing the crafted XPS document, thereby escalating to system level privileges.
OpenCVE Enrichment