Junglewise Threat Intelligence

CVE-2026-69456: Microsoft Windows Speech heap-based buffer overflow

CVE-2026-69456 · Severity: high · CVSS 7.8 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

A heap-based buffer overflow vulnerability in Windows Speech allows a local attacker with existing user account access to elevate their privileges to system level. Successful exploitation could grant an attacker complete control of the affected computer and access to all data and applications on it.

Technical details

A heap-based buffer overflow in Microsoft Windows Speech enables privilege escalation from an authenticated local context. The vulnerability requires the attacker to already have user-level access to execute the exploit, but once triggered, allows elevation to SYSTEM privileges. A patch is available from Microsoft.

Affected products

  • Microsoft Windows Speech

Timeline

  • 2026-09-08: disclosed

References

Related threats