Impact
A heap-based buffer overflow exists in the Windows Speech component, enabling a local attacker with authorized user privileges to gain higher privileges. The vulnerability results in the ability to execute arbitrary code with SYSTEM or a local administrator account, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is not available, suggesting limited publicly known exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker must be authenticated to the machine to exploit the overflow, after which they can elevate privileges to system-level.
OpenCVE Enrichment