CVE-2026-69367: Microsoft Standard XPS Information Disclosure Vulnerability
Published Sep 8, 2026
·Updated
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Affected Software
1 affected component
Microsoft Microsoft Standard XPS
Event History
Sep 8, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The CVSS vector indicates local access and low privileges are required. It does not indicate that the issue can be exploited remotely.
2
Does exploitation require a user to interact with attacker-controlled content?
No. The CVSS vector specifies that no user interaction is required.
3
What is the expected security impact?
The reported impact is high confidentiality loss, with no integrity or availability impact indicated by the CVSS vector.