Impact
A heap‑based buffer overflow in the Windows Audio Service allows an authorized local attacker to overwrite memory structures and gain elevated privileges, potentially reaching SYSTEM level. The flaw is a classic CWE‑122 vulnerability and can be leveraged by an attacker with user‑level access to run code with higher privileges.
Affected Systems
Affected are numerous Microsoft Windows releases: Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity. EPSS is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed live exploitation. Attackers must have local user access; the flaw permits privilege escalation to SYSTEM, which could allow full system compromise if exploited.
OpenCVE Enrichment