Junglewise Threat Intelligence

CVE-2026-69311: Microsoft Windows Audio Service use-after-free privilege escalation

CVE-2026-69311 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Audio Service is a core Windows component that manages audio playback and recording on computers. A use-after-free vulnerability allows an authorized attacker with local access to crash the service or execute arbitrary code, potentially gaining system-level privileges and full control of the affected computer.

Technical details

A use-after-free vulnerability exists in Microsoft Windows Audio Service, where freed memory is accessed after deallocation, leading to memory corruption. The vulnerability requires the attacker to be an authorized local user (not a guest or unauthenticated attacker). By crafting specific audio-related requests or triggering particular service states, an attacker can manipulate the freed memory and execute arbitrary code in the context of the Audio Service, which typically runs with elevated privileges. A patch is available from Microsoft.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats