Executive brief
A security vulnerability exists in the Windows Audio Service, which manages sound playback and recording on Windows computers. An attacker who already has basic access to a system could exploit this flaw to view sensitive information they are not authorized to see. This could lead to the exposure of private data, though it does not allow the attacker to take control of the system or delete files.
Technical details
This vulnerability is classified as an Information Exposure (CWE-200) within the Windows Audio Service. The flaw allows a locally authenticated attacker with low privileges to gain access to sensitive information that should be restricted. The attack vector is local, meaning the attacker must already have the ability to execute code on the target system, and no user interaction is required. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7376
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD