Impact
An out‑of‑bounds read in Microsoft Standard XPS allows an authorized local user to read data from memory that should not be exposed. The flaw results in disclosure of confidential information, such as sensitive application data or system memory contents, through local privilege access. It is a buffer overread vulnerability (CWE‑125).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2016, 2019, 2022, 2025 – including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score is < 1%, indicating a low likelihood of widespread exploitation. The vulnerability is local and requires an authorized attacker with user or administrative privileges, and it is not currently listed in CISA’s KEV catalog. Exploitation involves providing or opening a maliciously crafted XPS document with the Standard XPS viewer or related components, enabling the memory read and data disclosure.
OpenCVE Enrichment