Executive brief
The Realtek High Definition Audio Driver, which manages audio hardware on Windows computers, contains a configuration flaw. A local user with limited access can exploit this to run their own programs with full administrative (System) control. This could allow an attacker to take complete control of the machine, bypass security restrictions, or access sensitive data.
Technical details
The Realtek High Definition Audio Driver (specifically RtkAudioService) installs with an unquoted service path containing spaces (e.g., C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe). This is a CWE-428 vulnerability where the Windows Service Control Manager may misinterpret the path. A local attacker with write permissions to the root or intermediate directories can place a malicious executable (e.g., C:\Program.exe) that will be executed instead of the legitimate service binary upon the next service restart or system reboot. Because the service runs as LocalSystem, the attacker's code will execute with the highest possible privileges on the local machine. This was verified on version 6.0.1.6730 on Windows 7.
Affected products
- Realtek High Definition Audio Driver 6.0.1.6730
Timeline
- 2016-10-19: disclosed: Original exploit published on Exploit-DB
- 2026-06-19: advisory: NVD and VulnCheck published formal advisory details