CVE-2026-68890
massLocal Privilege Escalation via Heap Buffer Overflow in Microsoft Standard XPS
CVE-2026-68890 is a heap-based buffer overflow (CWE-122) in Microsoft Standard XPS, the XPS document/printing component shipped with Windows. A local attacker with low-privileged, authorized credentials can trigger the overflow without any user interaction, per the CVSS vector (AV:L/PR:L/UI:N). Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on the confidentiality, integrity, and availability of that host. Affected version ranges are not specified in the available data, so any Windows installation containing the Standard XPS component should be presumed potentially affected pending Microsoft's advisory. Exploitation status is currently benign: no known in-the-wild exploitation, no public proof-of-concept, not listed in CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-68890 via Windows Update as soon as it is released, prioritizing shared workstations, terminal/RDS servers, and other hosts where untrusted or low-privileged users can sign in locally. Because affected version ranges are not in the provided data, verify applicability against Microsoft's official advisory before deploying. Until patched, enforce least-privilege local accounts, since the flaw requires an authorized local user to trigger.
| Microsoft Standard XPS (XPS document/printing component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.