Executive brief
Windows Audio Service is a system component that manages audio playback and recording on Windows computers. A use-after-free vulnerability in this service allows an authenticated attacker to escalate their privileges to system level, potentially gaining complete control of the affected computer.
Technical details
A use-after-free vulnerability exists in Microsoft Windows Audio Service, where memory is accessed after it has been freed, leading to memory corruption. The vulnerability requires an attacker to be already authenticated on the system (local access required). By exploiting this flaw, an authorized user can escalate their privileges from standard user level to SYSTEM level. The attack vector is local only and does not require any user interaction beyond initial system access. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed