CVE-2026-68897
massHeap Buffer Overflow in Microsoft Standard XPS Allows Local Privilege Escalation
CVE-2026-68897 is a heap-based buffer overflow (CWE-122) in the Microsoft Standard XPS component, an XPS document/printing component maintained by Microsoft, who assigned the issue a CVSS 3.1 score of 7.0 (High). It is a local privilege elevation flaw: an attacker who already holds an authorized, low-privileged account on the machine can trigger the overflow via the component's handling of XPS content, requiring no user interaction, though the high attack complexity (AC:H) makes successful exploitation conditions difficult to arrange. A successful exploit elevates the attacker's privileges with high impact to confidentiality, integrity, and availability on the local system. Any system including the Microsoft Standard XPS component is potentially affected; the specific affected version ranges have not been provided in the available data. There is currently no evidence of active exploitation: the issue is not in CISA KEV, no public PoC exists, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's fix for CVE-2026-68897 via Windows Update when released, prioritizing hosts where untrusted or multiple local users log in (RDS/VDI servers, shared workstations, kiosks), since exploitation requires an existing local account. With no known exploitation, no public PoC, and EPSS at 0.2%, standard-cycle patching is reasonable, but treat local privilege escalations as high-value in hardening reviews because they frequently complete remote-to-local attack chains.
| Microsoft Standard XPS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.