Executive brief
A security vulnerability has been identified in the Microsoft Windows Speech component, which handles voice recognition and text-to-speech features. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A use-after-free vulnerability (CWE-416) exists in the Microsoft Windows Speech component. The flaw is triggered when the system attempts to access memory that has already been freed, which can be leveraged by a local attacker with low privileges to execute code in a higher-privileged context. Exploitation requires the attacker to have local access to the target machine and involves some level of user interaction. Successful exploitation results in a scope break, allowing the attacker to gain SYSTEM-level privileges. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD.
- 2026-07-14: patched: Security updates released by Microsoft.