ZeroHour

CVE-2026-68885

mass

Heap buffer overflow in Microsoft Standard XPS allows local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-68885 is a heap-based buffer overflow (CWE-122) in Microsoft Standard XPS, the XPS document component shipped as part of the Windows print/document pipeline. An attacker who already has a foothold as a standard user on the machine (CVSS AV:L/PR:L) can trigger the overflow by getting the component to process crafted document content, and no user interaction is required (UI:N). Successful exploitation elevates the attacker's privileges to a higher local context, with high impact on confidentiality, integrity, and availability — effectively full local compromise of the host. Any Windows installation that includes the Standard XPS component is affected, which by default means current Windows client and server deployments. Exploitation status: no public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.3%, 25th percentile) indicate no known exploitation at this time.

What to do: Install Microsoft's security update for CVE-2026-68885 via Windows Update as soon as it is offered, and check Microsoft's advisory for the affected/fixed Windows builds (not enumerated in the available data). Prioritize multi-user hosts — RDS/terminal servers, shared workstations, and VDI — where low-privilege local users log in, since exploitation requires local access; with no public PoC or in-the-wild exploitation known and EPSS at 0.3%, routine patch-cycle handling is reasonable for most environments.

Affected
Microsoft Standard XPS (XPS document/print component shipped with Windows)
Estimated exposure
masshundreds of millions of Windows endpoints (in-box Windows component) — estimate — Microsoft Standard XPS is an in-box component of Windows client and server editions rather than a separately installed add-on, so the potential install base is effectively the entire modern Windows fleet — on the order of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.