Description
Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in the Windows Speech component. When triggered by a user with legitimate local access, the flaw permits the attacker to write beyond a allocated buffer and execute arbitrary code with privileges higher than the user’s. This leads to elevation of privilege on the local system, potentially allowing the attacker to take full system control if the user can obtain SYSTEM rights.

Affected Systems

Affected devices include Microsoft Windows 10 (all listed builds 1607, 1809, 21H2, 22H2), Windows 11 (builds 23H2, 24H2, 25H2, 26H1), and Windows Server editions (2016, 2019, 2022, 2025, in both full and Server Core installations). Each affected platform contains the vulnerable Speech engine component that can be abused when a user with local authorization runs the compromised code.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity local privilege escalation. EPSS is not available, so the likelihood of real‑world exploitation cannot be quantifiably measured, and the vulnerability is not listed in the CISA KEV catalog. Attack requires local user privileges, making it a local privilege escalation rather than a remote vulnerability. If an attacker already has a user account on the machine, the flaw provides a clear path to elevate to system level and can be used to compromise confidentiality, integrity and availability of the affected system.

Generated by OpenCVE AI on September 8, 2026 at 22:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the cumulative update for the relevant Windows or Windows Server version by following the Microsoft Security Advisory page for CVE-2026-69444 and apply the patch at the earliest opportunity.
  • Restart the affected system to activate the update.
  • If the patch cannot be applied immediately, disable the Windows Speech service on each target system to prevent exploitation until the official update is installed.

Generated by OpenCVE AI on September 8, 2026 at 22:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Title Microsoft Windows Speech Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:38:40.999Z

Reserved: 2026-08-03T20:59:32.784Z

Link: CVE-2026-69444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:08.667

Modified: 2026-09-08T19:23:00.357

Link: CVE-2026-69444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T22:15:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow