Impact
This vulnerability is an out‑of‑bounds read in the Microsoft Standard XPS component. It permits an attacker who already has authorized access to the local system to read memory areas beyond a buffer, potentially exposing sensitive data such as passwords, cryptographic keys, or other confidential information. The weakness is identified as a buffer overread (CWE‑125) and an incorrect type conversion (CWE‑843). The resulting impact is the disclosure of information that the attacker could otherwise not see, which compromises confidentiality but does not affect integrity or availability.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 (across x86, x64, and ARM architectures); and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations). All these releases contain the Microsoft Standard XPS component that is vulnerable.
Risk and Exploitability
The CVSS score of 5.5 places this vulnerability in the Medium range. No EPSS data is available, suggesting limited publicly known exploitation or unknown exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, indicating no active known exploitation at this time. The likely attack vector is a local privileged or authorized user who can create or manipulate XPS files, leading to the out‑of‑bounds read. Because the attacker must already possess local access, the risk to an unauthenticated external actor is low. However, any compromised local session, including those from malware or stolen credentials, could exploit this flaw to exfiltrate sensitive memory contents.
OpenCVE Enrichment