Executive brief
The Kernel Streaming WOW Thunk Service Driver, a Windows system component responsible for audio processing compatibility, contains a memory safety vulnerability that allows an authenticated attacker to escalate privileges on a local system. Exploitation requires prior access to an authorized user account and could enable an attacker to gain administrative control of the affected computer.
Technical details
This vulnerability is an untrusted pointer dereference in the Kernel Streaming WOW Thunk Service Driver. The vulnerability allows an authorized local attacker to execute arbitrary code in kernel context, leading to privilege escalation. The attack vector requires authentication (the attacker must be a logged-in user on the system) and local code execution capability. A successful exploit grants the attacker kernel-level privileges, enabling complete system compromise. Microsoft has issued patches to address this vulnerability.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Security updates available from Microsoft