Impact
The vulnerability is an out‑of‑bounds read in Microsoft Standard XPS, which allows an attacker with local, authorized privileges to read data that the application should not have access to. Because it is a read‑only information disclosure, the attacker is unable to modify system state but could obtain sensitive data from memory. The weakness is catalogued as CWE‑125, denoting an out‑of‑bounds read.
Affected Systems
Affected systems include Microsoft Windows 10 (Versions 1607, 1809, 21H2, 22H2) and Windows 11 (Versions 23H2, 24H2, 25H2, 26H1) as well as Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both full and core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the vulnerability is classified as a local privilege issue that requires an authorised user. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low but non-zero likelihood of exploitation in the wild. An attacker would need local access and the ability to launch the XPS component or an application that uses it. No remote attack vector is described.
OpenCVE Enrichment