ZeroHour

CVE-2026-68892

mass

Local Privilege Elevation via Heap Buffer Overflow in Microsoft Standard XPS

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-68892 is a heap-based buffer overflow (CWE-122) in Microsoft Standard XPS, Microsoft's XML Paper Specification component. An authorized attacker who already holds valid low-privileged local credentials (CVSS AV:L/PR:L, no user interaction required) can trigger the overflow, most plausibly by having the component process crafted XPS content. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability. Any system running the affected Microsoft Standard XPS component is exposed, although the available data does not specify which Windows versions or builds are affected. There is no known public proof of concept, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.2% probability of exploitation within 30 days (16th percentile), indicating no known exploitation to date.

What to do: Apply Microsoft's security update for CVE-2026-68892 as soon as it is available, and check Microsoft's advisory for the exact affected Windows versions and builds. Because exploitation requires local access, prioritize patching multi-user systems such as RDS/VDI hosts and shared workstations where untrusted users can log on locally. No public PoC, KEV listing, or workarounds are known; monitor Microsoft and CISA advisories for updates on exploitation status.

Affected
Microsoft Standard XPS
Estimated exposure
masson the order of hundreds of millions to ~1 billion Windows installations (component ships with the OS) — Standard XPS is a Microsoft Windows component present by default on essentially all Windows desktop installations (publicly estimated at well over a billion active devices), although practical exploitability is limited to systems where…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.