Executive brief
A heap-based buffer overflow vulnerability exists in Windows Audio Service, a core component that manages audio playback and recording on Windows systems. An authenticated attacker with local access could exploit this vulnerability to gain system-level privileges, potentially allowing them to install malware, steal data, or take full control of the affected machine.
Technical details
A heap-based buffer overflow in Windows Audio Service enables privilege escalation through a local attack vector. The vulnerability requires prior authentication and local system access; successful exploitation grants the attacker elevated privileges on the compromised system.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed