Impact
The vulnerability is a use‑after‑free flaw in the Windows Audio Service. An attacker who already has authorized local access can trigger the fault and gain elevated privileges. The flaw can lead to execution of code with higher privileges, allowing the attacker to modify system settings, access sensitive data, or install malware. It is classified as CWE‑416, an improper use of memory after it has been freed.
Affected Systems
Affected systems include all supported Microsoft Windows releases and servers listed in the CNA entry: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server versions 2012 R2, 2016, 2019, 2022, 2025. The issue is present on both x86 and x64 architectures, as well as on ARM64 for the Windows 11 releases, according to the CPE data. All these products remain vulnerable until the update is applied.
Risk and Exploitability
The CVSS score is 7, indicating high severity. EPSS data is not available, so exploitation probability remains unknown, but the flaw is local and requires an attacker with legitimate user rights. The vulnerability is not listed in the CISA KEV catalog, suggesting that no publicly documented exploits are currently known. A local attacker can exploit the flaw by sending specially crafted audio data or otherwise triggering the service to consume freed memory. Because the attack vector is local, the compromise remains confined to the victim machine, but successful privilege escalation can lead to full system takeover. Systems that have not applied the Microsoft update therefore remain exposed.
OpenCVE Enrichment