Junglewise Threat Intelligence

CVE-2026-69531: Microsoft Windows Speech confused deputy vulnerability

CVE-2026-69531 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Microsoft Windows Speech contains a confused deputy vulnerability that allows a local, authenticated user to tamper with system resources. An attacker with valid credentials could potentially modify or corrupt speech-related functionality or adjacent system components, affecting system integrity and potentially impacting services that depend on speech recognition.

Technical details

This is a confused deputy (unintended proxy/intermediary) vulnerability in the Windows Speech component. The flaw allows an authorized local attacker to perform tampering actions by exploiting the way Speech processes requests or accesses resources. The attack requires local access and prior authentication. An attacker can achieve privilege escalation or tampering with protected resources through the vulnerable component acting as an unintended intermediary. A patch has been released by Microsoft.

Affected products

  • Microsoft Windows Speech

Timeline

  • 2026-09-08: disclosed

References

Related threats