CVE-2026-68889
massHeap Buffer Overflow in Microsoft Standard XPS Enables Network Privilege Escalation
CVE-2026-68889 is a heap-based buffer overflow (CWE-122), apparently arising from an integer overflow or wraparound (CWE-190), in Microsoft Standard XPS, a component of the Windows XPS document/print stack. The CVSS vector (AV:N/AC:H/PR:L/UI:R) indicates a local or network-adjacent, low-privilege authorized attacker can trigger the flaw when crafted XPS content is processed, with some form of user interaction required, and the hard attack complexity suggests exploitation conditions are non-trivial. Successful exploitation yields elevation of privilege on the affected system, with high impact to confidentiality, integrity, and availability. Any Windows environment where users or low-privilege accounts can submit XPS content to the affected component is potentially affected. Exploitation status is currently quiet: no entry in CISA's KEV, no known public proof-of-concept, and EPSS puts 30-day exploitation probability at only 0.4%.
What to do: Apply the security update Microsoft released for CVE-2026-68889 as soon as patching windows allow, prioritizing multi-user systems and servers where untrusted or low-privilege users can submit print/XPS jobs. Inventory endpoints for the Standard XPS/XPS print components and verify patch status after deployment; until patched, restrict which accounts can submit XPS content to shared or exposed systems. Given low EPSS and no KEV listing, treat this as routine high-priority patching rather than an emergency, but do not defer indefinitely given the high-impact privilege escalation outcome.
| Microsoft Standard XPS (Windows XPS document/print component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122, CWE-190
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.