Impact
A heap‑based buffer overflow exists in the Windows Audio Service that allows an authorized local user to gain higher privileges. The vulnerability is a classic example of CWE‑122, where improper bounds checking leads to a memory corruption that can be abused to execute code with elevated rights. An attacker who can run a program on the machine could exploit this flaw to acquire SYSTEM level privileges, thereby gaining full control over the affected device.
Affected Systems
Microsoft Windows 11 version 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025, including the Server Core installation. All architectures listed in the CNA information are impacted, with the vulnerable audio service running on both ARM64 and x64 platforms.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity exploitation scenario, and while the EPSS score is not available, the absence of a KEV listing does not diminish the local threat. The flaw can be triggered by any user who has permission to run code on the system, making it trivially exploitable in environments where user accounts have higher privileges or where the audio service runs with elevated rights. Because this is a local elevation of privilege, it is effective only when the attacker already has access to the machine, but the result of the exploit is a complete compromise of that system.
OpenCVE Enrichment