Executive brief
A security vulnerability exists in the Quality Windows Audio/Video Experience (QWAVE) service, a Windows component that helps manage network performance for streaming media. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt operations.
Technical details
A use-after-free vulnerability (CWE-416) exists within the Quality Windows Audio/Video Experience (QWAVE) service in multiple versions of Microsoft Windows. The flaw is triggered when the service improperly handles objects in memory, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the system with low-level user privileges. Successful exploitation allows the attacker to execute code with elevated system privileges, potentially leading to a full compromise of the host. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory