CVE-2026-68885
massHeap buffer overflow in Microsoft Standard XPS allows local privilege escalation
CVE-2026-68885 is a heap-based buffer overflow (CWE-122) in Microsoft Standard XPS, the XPS document component shipped as part of the Windows print/document pipeline. An attacker who already has a foothold as a standard user on the machine (CVSS AV:L/PR:L) can trigger the overflow by getting the component to process crafted document content, and no user interaction is required (UI:N). Successful exploitation elevates the attacker's privileges to a higher local context, with high impact on confidentiality, integrity, and availability — effectively full local compromise of the host. Any Windows installation that includes the Standard XPS component is affected, which by default means current Windows client and server deployments. Exploitation status: no public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.3%, 25th percentile) indicate no known exploitation at this time.
What to do: Install Microsoft's security update for CVE-2026-68885 via Windows Update as soon as it is offered, and check Microsoft's advisory for the affected/fixed Windows builds (not enumerated in the available data). Prioritize multi-user hosts — RDS/terminal servers, shared workstations, and VDI — where low-privilege local users log in, since exploitation requires local access; with no public PoC or in-the-wild exploitation known and EPSS at 0.3%, routine patch-cycle handling is reasonable for most environments.
| Microsoft Standard XPS (XPS document/print component shipped with Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.