Impact
An integer underflow (wrap or wraparound) within the Microsoft Standard XPS component can be triggered by a malicious input. The flaw allows an attacker who can deliver a crafted XPS payload to the target system to execute arbitrary code with the privileges of the local application. The vulnerability is classified as a high‑severity remote code execution weakness.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations.
Risk and Exploitability
The CVSS base score of 9.8 indicates the exploit offers full confidentiality, integrity, and availability compromise. While no EPSS score is published, the lack of containment mechanisms combined with the network‑based delivery vector makes real‑world exploitation a serious threat. The vulnerability is not yet listed in the CISA KEV catalog, but the high severity and the potential for widespread impact warrant urgent assessment. An attacker would likely encode a malicious payload within an XPS document and force the target to process it through the exposed XPS service, resulting in arbitrary code execution.
OpenCVE Enrichment