Impact
A heap‑based buffer overflow exists in the Windows Speech component. When triggered by a user with legitimate local access, the flaw permits the attacker to write beyond a allocated buffer and execute arbitrary code with privileges higher than the user’s. This leads to elevation of privilege on the local system, potentially allowing the attacker to take full system control if the user can obtain SYSTEM rights.
Affected Systems
Affected devices include Microsoft Windows 10 (all listed builds 1607, 1809, 21H2, 22H2), Windows 11 (builds 23H2, 24H2, 25H2, 26H1), and Windows Server editions (2016, 2019, 2022, 2025, in both full and Server Core installations). Each affected platform contains the vulnerable Speech engine component that can be abused when a user with local authorization runs the compromised code.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation. EPSS is not available, so the likelihood of real‑world exploitation cannot be quantifiably measured, and the vulnerability is not listed in the CISA KEV catalog. Attack requires local user privileges, making it a local privilege escalation rather than a remote vulnerability. If an attacker already has a user account on the machine, the flaw provides a clear path to elevate to system level and can be used to compromise confidentiality, integrity and availability of the affected system.
OpenCVE Enrichment