Impact
A heap-based buffer overflow occurs in the Windows Audio Service, enabling an attacker who has local administrative privileges or other authorized access to elevate privileges further. The flaw allows overwriting critical memory structures which can lead to execution of arbitrary code with higher privileges, compromising system integrity and confidentiality.
Affected Systems
Affected products include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025) across full installs and Server Core installations.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate to high severity. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation but still significant potential. The likely attack vector is local, with an authorized user triggering the overflow via an application that interfaces with the audio service. If exploited, it can lead to full system compromise through privilege escalation.
OpenCVE Enrichment