ZeroHour

CVE-2026-68890

mass

Local Privilege Escalation via Heap Buffer Overflow in Microsoft Standard XPS

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-68890 is a heap-based buffer overflow (CWE-122) in Microsoft Standard XPS, the XPS document/printing component shipped with Windows. A local attacker with low-privileged, authorized credentials can trigger the overflow without any user interaction, per the CVSS vector (AV:L/PR:L/UI:N). Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on the confidentiality, integrity, and availability of that host. Affected version ranges are not specified in the available data, so any Windows installation containing the Standard XPS component should be presumed potentially affected pending Microsoft's advisory. Exploitation status is currently benign: no known in-the-wild exploitation, no public proof-of-concept, not listed in CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-68890 via Windows Update as soon as it is released, prioritizing shared workstations, terminal/RDS servers, and other hosts where untrusted or low-privileged users can sign in locally. Because affected version ranges are not in the provided data, verify applicability against Microsoft's official advisory before deploying. Until patched, enforce least-privilege local accounts, since the flaw requires an authorized local user to trigger.

Affected
Microsoft Standard XPS (XPS document/printing component)
Estimated exposure
masshundreds of millions of Windows devices (component ships with Windows) — The Standard XPS/XPS Document Writer component is present by default on most Windows installations, and Windows runs on well over a billion devices worldwide, so the plausibly affected install base is in the hundreds of millions, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.