Impact
The vulnerability is a double free in the Windows Audio Service, allowing a local authorized attacker to elevate privileges. This flaw falls under CWE‑415 and results in the attacker gaining higher privileges on the same system.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (versions 23H2, 24H2, 25H2, 26H1, including ARM 64 variants), as well as Windows Server 2012 through 2025, including both Server Core and full installations, are affected. The issue is specific to the Windows Audio Service component.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is listed as not part of CISA KEV. The attack requires a local user with sufficient permissions to execute code that triggers the double free; once exploited, the attacker can run with elevated privileges on the affected system. No public exploit information is provided, but the local nature of the attack vector and the high severity suggest that the risk should be treated as significant.
OpenCVE Enrichment