Impact
The vulnerability is an unintended proxy or intermediary in the Windows Speech subsystem. It is classified as a confused deputy (CWE‑441), allowing an attacker who already has authorized access to tamper with speech‑related functionality or data. The impact is the ability to modify or replace speech inputs or outputs, potentially leading to misinformation or manipulation of voice‑based interactions.
Affected Systems
Affected installations include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and the corresponding Windows Server releases 2016, 2019, 2022, and 2025—both standard and server‑core configurations. The impact applies to both x86 and x64 architectures across these releases.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity, and the EPSS score is unavailable, suggesting no publicly known exploitation prevalence. The vulnerability is not listed in the CISA KEV catalog. Based on the description the attack vector appears to be local; an attacker must already possess authorized system access. The risk to unauthorized users is limited, but within an authorized session the attacker can tamper with voice data or commands, which may undermine trust in automated voice interfaces.
OpenCVE Enrichment