CVE-2026-69313
massHeap Buffer Overflow in Microsoft Standard XPS Enables Privilege Escalation
Microsoft Standard XPS, a Windows component used to process and render XPS document/printing content, contains a heap-based buffer overflow (CWE-122) that Microsoft classifies as an elevation-of-privilege vulnerability. An attacker must be an authorized (low-privileged) user and get a victim to trigger processing of maliciously crafted content, likely a crafted XPS document or print job, since the CVSS vector requires network access, high attack complexity, and user interaction (AV:N/AC:H/PR:L/UI:R). Successful exploitation corrupts heap memory in the component and allows the attacker to elevate privileges on the host, with high impact on confidentiality, integrity, and availability. Any Windows system that includes the Standard XPS component is affected per Microsoft's advisory; the source data does not specify exact Windows version ranges, so defenders should consult Microsoft's bulletin for the affected releases. There is currently no public proof-of-concept, no CISA KEV listing, and no known in-the-wild exploitation, and EPSS assigns only a 0.5% probability of exploitation within 30 days (43rd percentile).
What to do: Apply the Windows security update from Microsoft's Patch Tuesday release that addresses CVE-2026-69313 on all systems listed as affected in the advisory, since Microsoft has not published a workaround in the available data. Because there is no public PoC or in-the-wild exploitation and EPSS is low (0.5%), this can be handled in the normal patch cycle, but consider prioritizing shared/user-facing hosts. In the interim, caution users against opening XPS documents or print content from untrusted sources.
| Microsoft Standard XPS (Windows XPS document/printing component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.