Description
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in the Windows Audio Service that allows an authorized local user to gain higher privileges. The vulnerability is a classic example of CWE‑122, where improper bounds checking leads to a memory corruption that can be abused to execute code with elevated rights. An attacker who can run a program on the machine could exploit this flaw to acquire SYSTEM level privileges, thereby gaining full control over the affected device.

Affected Systems

Microsoft Windows 11 version 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025, including the Server Core installation. All architectures listed in the CNA information are impacted, with the vulnerable audio service running on both ARM64 and x64 platforms.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity exploitation scenario, and while the EPSS score is not available, the absence of a KEV listing does not diminish the local threat. The flaw can be triggered by any user who has permission to run code on the system, making it trivially exploitable in environments where user accounts have higher privileges or where the audio service runs with elevated rights. Because this is a local elevation of privilege, it is effective only when the attacker already has access to the machine, but the result of the exploit is a complete compromise of that system.

Generated by OpenCVE AI on September 8, 2026 at 21:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows Security Update from the Microsoft Security Update Guide for the affected Windows 11 and Windows Server 2025 releases
  • Configure user accounts to run only with the minimal privileges required for their tasks, removing unnecessary local administrator rights
  • If the Windows Audio Service is not required for business operations, disable the service to eliminate the attack surface

Generated by OpenCVE AI on September 8, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Title Windows Audio Service Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:38:38.754Z

Reserved: 2026-08-03T21:03:33.030Z

Link: CVE-2026-69447

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:09.017

Modified: 2026-09-08T19:23:00.357

Link: CVE-2026-69447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:45:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow