Error Messages to Fuzzing: Detecting XPS Parsing Vulnerabilities in Windows Printing Components
Yunpeng Tian, Feng Dong, Junhai Wang, Mu Zhang, Zhiniang Peng, Zesen Ye, Xiapu Luo, Haoyu Wang
Abstract
Windows printing services remain a notable vector for attacks. Previous studies have predominantly targeted vulnerabilities within various control aspects of printing services, such as spooler services and firmware updates. Yet, we contend that an essential aspect of data processing—the document parser within printer drivers—has been overlooked in past research. We present a coverage-based fuzzing system, PrintXPSurge, specifically crafted to detect weaknesses in the XPS printer driver's parsing function. To craft semantically correct XPS files, we leverage a large language model-assisted repair approach to automate the creation of semantically correct XPS files that comply with necessary constraints. To ensure our fuzzing process effectively interacts with the XPS printer driver, we develop a progressive state reconstruction method that addresses individual dependency requirements across the entire printing service workflow. Furthermore, when a crash is detected, we employ backtracing to confirm its origin in the XPS parser, isolating it from other components in the pipeline. Our evaluation reveals that PrintXPSurge surpasses existing top Windows fuzzers in performance, successfully identifying 102 bugs in 10 drivers from major brands, including 17 zero-day vulnerabilities confirmed by Microsoft and third-party vendors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bda8079f-5aa0-4599-901c-59257d964ca5Cited by top-tier papers2
- Thinking More, Harnessing Better: Automatic Harness Generation with Dataflow Aggregation and Workflow DecompositionXing Zhang, Zikang Huang, Gang Yang, CongChong Wang et al.CCS 2026
- Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows EcosystemFeng Dong, Jianting Gao, Yunpeng Tian, Weifeng Yuan et al.USENIX Security 2026
Builds on12
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- GRIMOIRE: Synthesizing Structure while FuzzingTim Blazytko, Cornelius Aschermann, Moritz Schlögel, Ali Abbasi et al.USENIX Security 2019 · 123 citations
- WhiteFox: White-Box Compiler Fuzzing Empowered by Large Language ModelsChenyuan Yang, Yinlin Deng, Runyu Lu, Jiayi Yao et al.OOPSLA 2024 · 74 citations
- LLMIF: Augmented Large Language Model for Fuzzing IoT DevicesJincheng Wang, Le Yu, Xiapu LuoS&P 2024 · 61 citations
- NtFuzz: Enabling Type-Aware Kernel Fuzzing on Windows with Static Binary AnalysisJaeseung Choi, Kangsu Kim, Daejin Lee, Sang Kil ChaS&P 2021 · 61 citations
Related papers
- From Documentation to Zero-day Vulnerabilities: LLM-Driven Fuzzing of JavaScript Engines in PDF ReadersSuyue Guo, Stijn Pletinckx, Tianle Yu, Yigitcan Kaya et al.CCS 2026
- Unlocking Low Frequency Syscalls in Kernel Fuzzing with Dependency-Based RAGZhiyu Zhang, Longxing Li, Ruigang Liang, Kai ChenISSTA 2025 · 3 citations
- Specializing Language Models for Textual Fuzzing via Reinforcement LearningJiayi Lin, Liangcai Su, Junzhe Li, Chenxiong QianS&P 2026
- LifeFuzz: Lifecycle-Guided Fuzzing for Windows Driver Cross-Handler VulnerabilitiesChendong Yu, Yuekang Li, Yang Xiao, Jie Lu et al.EuroSys 2026
- ELFuzz: Efficient Input Generation via LLM-driven Synthesis Over Fuzzer SpaceChuyang Chen, Brendan Dolan-Gavitt, Zhiqiang LinUSENIX Security 2025
