Microsoft’s advisory describes a heap-based buffer overflow in Microsoft Standard XPS that allows an authorized attacker to elevate privileges locally. The weakness is classified as CWE-122, and its CVSS vector is CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C.
The preconditions narrow the immediate exposure but do not make the patch optional. An attacker needs local access and low-level credentials, while Microsoft says successful exploitation requires winning a race condition. If successful, the advisory says an attacker could move from Medium Integrity Level to Local Service, a privilege boundary relevant to endpoint persistence and to post-compromise activity on multi-user and managed systems.
Publicly disclosed: No
Exploited: No
Customer action required: Yes
Microsoft’s exploitation assessment is Exploitation Unlikely. That assessment reflects the high attack complexity identified in the CVSS metrics, specifically the required race condition; it does not change the fact that the flaw can affect confidentiality, integrity, and availability if the race is won.
Why the XPS component needs patch coverage
Microsoft Standard XPS is part of Windows’ document and printing stack, which can leave it present on systems where users rarely consciously handle XPS files. The advisory’s local attack vector means CVE-2026-68897 does not describe a remote, unauthenticated entry point. Its value to an attacker would come after they already obtained authorized access at Medium Integrity Level.
For security teams, that places this CVE in the defense-in-depth portion of a patch program: it can turn an ordinary user-context foothold into Local Service if exploitation succeeds. The affected-product record also spans Server Core variants, so server patch compliance reports should not exclude headless installations on the assumption that XPS-related fixes apply only to desktop deployments.
Windows 10 and Windows 11 fixed builds
Microsoft maps Windows 10 Version 1607 for 32-bit Systems (x86) and Windows 10 Version 1607 for x64-based Systems to KB5123099, fixed build 10.0.14393.9512. For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1809 for 32-bit Systems (x86) and Windows 10 Version 1809 for x64-based Systems require KB5122876, fixed build 10.0.17763.9245. For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
Windows 10 Version 21H2 for 32-bit Systems (x86), Windows 10 Version 21H2 for ARM64-based Systems, and Windows 10 Version 21H2 for x64-based Systems use KB5122878 and fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
For Windows 10 Version 22H2 for 32-bit Systems (x86), Windows 10 Version 22H2 for ARM64-based Systems, and Windows 10 Version 22H2 for x64-based Systems, Microsoft maps KB5122878 to fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 11 Version 23H2 for ARM64-based Systems and Windows 11 Version 23H2 for x64-based Systems require KB5122880, fixed build 10.0.22631.7582. For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
Microsoft maps Windows 11 Version 24H2 for ARM64-based Systems and Windows 11 Version 24H2 for x64-based Systems to KB5124008, fixed build 10.0.26100.9445. For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
Windows 11 Version 25H2 for ARM64-based Systems and Windows 11 Version 25H2 for x64-based Systems also use KB5124008, but their fixed build is 10.0.26200.9445. For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 version 26H1 for x64-based Systems require KB5124012 and fixed build 10.0.28000.2954. For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954. For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
Windows Server fixed builds
Windows Server 2012 (Server Core installation) (x64) and Windows Server 2012 (x64) require KB5123065, fixed build 6.2.9200.26349. For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349. For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 R2 (Server Core installation) (x64) and Windows Server 2012 R2 (x64) require KB5123066, fixed build 6.3.9600.23397. For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23397. For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23397.
Microsoft maps Windows Server 2016 (Server Core installation) (x64) and Windows Server 2016 (x64) to KB5123099, fixed build 10.0.14393.9512. For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2019 (Server Core installation) (x64) and Windows Server 2019 (x64) require KB5122876, fixed build 10.0.17763.9245. For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2022 (Server Core installation) (x64) and Windows Server 2022 (x64) require KB5122882, fixed build 10.0.20348.5622. For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622. For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2025 (Server Core installation) (x64) and Windows Server 2025 (x64) require KB5122871, fixed build 10.0.26100.33438. For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438. For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
Deployment priority and verification
Microsoft’s advisory establishes a clear operational action: install the KB assigned to each operating-system branch, then confirm the system has reached its specified fixed build. Because several KBs cover more than one release family but produce different build numbers—especially KB5122878 and KB5124008—administrators should validate against both the OS version and the target build, not the KB identifier alone.
For organizations staging updates, CVE-2026-68897 belongs in the same deployment wave as other September security fixes for endpoints and servers. The race-condition requirement makes reliable exploitation harder, but a successful attack would cross from Medium Integrity Level to Local Service; systems remain exposed until the relevant KB and fixed build are in place.