Impact
A heap‑based buffer overflow in the Windows Audio Service lets an attacker who can already run code or manipulate data locally write beyond the intended buffer and gain elevated privileges. The flaw is a classic stack corruption vulnerability classified as CWE‑122, and it can be triggered by specially crafted input that is processed by the audio service. Because the exploitation requires local access, an attacker would normally need to be logged on as a user with some level of authority to deliver the payload, but the resulting privilege escalation could allow full system compromise and control over all processes.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2019, 2022, and 2025 (including Server Core editions).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and while the EPSS metric is not available, the known lack of an early exploit and its inclusion in the Microsoft patch set suggests the real-world exploitation probability is uncertain but potentially significant. The vulnerability was not listed in the CISA KEV catalog, implying no known widespread active exploitation at the time of this analysis. If an attacker can run code locally, the flat attack vector can be leveraged to compromise the local machine and take full control of its resources.
OpenCVE Enrichment