CVE-2026-69824
massUnauthenticated RCE via Integer Underflow in Microsoft Standard XPS
CVE-2026-69824 is an integer underflow (CWE-191) in Microsoft's Standard XPS component that wraps a length or size value, causing memory corruption (CWE-122, heap-based buffer overflow) during processing of crafted XPS content. The flaw is rated critical (CVSS 9.8) with a network attack vector, low complexity, and no privileges or user interaction required, indicating an unauthenticated attacker can reach the vulnerable parsing path over the network. Successful exploitation allows arbitrary code execution with high impact on confidentiality, integrity, and availability on the affected system. All deployments of Microsoft Standard XPS are potentially affected; the available data does not specify which Windows versions or builds are impacted, so defenders should consult Microsoft's advisory for covered releases. There is no evidence of in-the-wild exploitation, no public proof-of-concept, and CISA has not added it to the KEV catalog; EPSS currently estimates a 1.0% chance of exploitation within 30 days.
What to do: Track Microsoft's security advisory for CVE-2026-69824 and apply the patched updates for the Standard XPS component as soon as they are released, since no specific fixed versions are listed in the current data. In the interim, inventory systems for the Standard XPS/XPS Document Writer component and restrict or firewall any network-facing service that processes XPS content. Given the unauthenticated, network-exploitable nature (CVSS 9.8) and no known exploitation yet, patching promptly is low-cost insurance before a PoC or in-the-wild activity emerges.
| Microsoft Standard XPS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122, CWE-191
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.