Executive brief
Windows Audio Service, a core component of the Microsoft Windows operating system responsible for processing audio, contains a heap buffer overflow vulnerability. An authorized attacker with local system access could exploit this flaw to execute code with elevated privileges, potentially compromising the entire system and any data stored on it.
Technical details
A heap-based buffer overflow exists in Windows Audio Service that allows an authorized local attacker to elevate privileges. The vulnerability requires the attacker to have local access to the affected system and existing authorization on that system. Successful exploitation enables arbitrary code execution with elevated privileges. The CVSS score of 7.8 indicates high severity with significant impact to system confidentiality, integrity, and availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Audio Service
Timeline
- 2026-09-08: disclosed