Junglewise Threat Intelligence

CVE-2026-70562: Microsoft Windows Audio Service double free privilege escalation

CVE-2026-70562 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

The Windows Audio Service is a core system component that manages audio playback and recording on Windows systems. A double free memory corruption vulnerability allows an authorized local user to crash the service or execute arbitrary code with elevated privileges, potentially compromising the entire system.

Technical details

A double free vulnerability exists in the Windows Audio Service, a kernel-level system component. The vulnerability is triggered through a memory management defect where a pointer is freed twice, leading to heap corruption. An attacker with local system access and authorization to interact with audio subsystem APIs can trigger this flaw to corrupt memory and achieve arbitrary code execution with elevated privileges. This is a local attack vector requiring prior system access; no network exploitation is possible.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats