Impact
A use‑after‑free bug in the Windows Audio Service allows an attacker who already has authenticated access on a Windows machine to increase their privileges locally. Exploiting the flaw can grant the attacker the ability to execute arbitrary code or modify system configurations with elevated rights, thereby compromising the integrity of the operating system and potentially exposing confidential data or enabling persistence.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server 2019, Windows Server 2022 and Windows Server 2025, including Server Core installations. The flaw is present across x86, x64 and ARM64 architectures as specified.
Risk and Exploitability
The CVSS score of 7 indicates a high severity for local privilege escalation. The EPSS score is currently unavailable, but the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation is known. The exploit requires an authorized user on the target system, and the attacker must trigger a use‑after‑free sequence in the Audio Service, implying that remote exploitation is not supported.
OpenCVE Enrichment