Impact
Use after free in the Windows Audio Service can be exploited by an authorized local attacker to gain higher privileges on the affected system. This vulnerability allows an attacker who already has some local access to bypass normal permission boundaries and run code with elevated rights. The weakness is a classic use‑after‑free flaw, identified as CWE‑416, which can compromise the confidentiality, integrity, and availability of the system if exploited.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Standard and Server Core installations).
Risk and Exploitability
The CVSS score of 7.0 classifies this flaw as Medium severity. Exploitation requires a local authorized attacker and is facilitated by a use‑after‑free condition in the audio service, which can be triggered by interacting with audio functions from userland. Epistemic data shows the EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog, indicating that it has not been widely observed in the wild yet. Nevertheless, the local nature of the attack vector means any user with access to a compromised or compromised system can elevate privileges if the updates are not applied.
OpenCVE Enrichment