ZeroHour

CVE-2026-69269

mass

Local Privilege Escalation via Integer Underflow in Microsoft Standard XPS

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69269 is an integer underflow (wrap/width wraparound, CWE-191) in Microsoft Standard XPS, the XPS document/printing component shipped by Microsoft. By supplying input that drives a length or size value below zero, a local, authorized (low-privileged) user can trigger the flaw without user interaction and corrupt memory handling in the component. Successful exploitation elevates the attacker from low privileges to higher local privileges, with high impact on confidentiality, integrity, and availability on the compromised host. Any Windows system with the Standard XPS component is potentially affected, though exploitation requires an attacker to already have local code execution or a local account. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS is low at 0.3% (25th percentile), suggesting limited near-term exploitation risk.

What to do: Apply Microsoft's security update for Standard XPS as soon as it is available via Windows Update, and verify build-specific applicability against Microsoft's advisory since affected version ranges are not listed here. Prioritize patching shared, multi-user, and VDI/kiosk endpoints where local low-privileged accounts are common, as this flaw requires local access to exploit. No public PoC or in-the-wild exploitation is known, so routine patch cadence is reasonable absent further intelligence.

Affected
Microsoft Standard XPS
Estimated exposure
mass>1 billion installations (XPS components ship with Windows client and server operating systems) — The Standard XPS component is distributed with Windows, whose installed base is on the order of a billion devices, so nearly all Windows endpoints are plausibly affected even though actual exploitability depends on local access and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Weakness
CWE-191
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.