Impact
A use‑after‑free flaw in the Windows Speech Runtime allows an authenticated local user to invoke code that receives higher privileges. The vulnerability is classified as CWE‑416 and results in the attacker gaining administrative level access, enabling the compromise of system confidentiality, integrity, or availability.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607 to 22H2 on both x86 and x64, Windows 11 versions 24H2 to 26H1 on ARM64 and x64, and all Windows Server releases 2016 through 2025, including Server Core installations. The issue resides solely in the Windows Speech component.
Risk and Exploitability
The CVSS score of 7.5 marks the vulnerability as high severity, yet the EPSS score is below 1%, indicating a low current exploitation likelihood. It is not listed in CISA KEV. Based on the description, it is inferred that the attack requires local authentication and execution of the speech service, after which the use‑after‑free can be triggered to elevate to system level privileges.
OpenCVE Enrichment