ZeroHour

CVE-2026-69311

mass

Use-after-free in Windows Audio Service enables local privilege escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69311 is a use-after-free memory-safety flaw (CWE-416) in the Windows Audio Service, a core Windows component that manages audio sessions and devices. It is triggered locally: an attacker who already holds a low-privileged account on the target system must induce the service to access memory that has been freed, which the CVSS vector marks as high-complexity (AC:H) and requiring no user interaction. Successful exploitation lets the attacker elevate privileges on the local machine (with high impact on confidentiality, integrity, and availability), typically by running code in the context of the audio service — a stepping stone to full system control that is commonly chained with other flaws. Any Windows installation is potentially affected, though the available data does not specify affected version ranges or SKUs. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.3% probability of exploitation in the next 30 days, so no active exploitation is currently known.

What to do: Apply the Microsoft security update that addresses CVE-2026-69311 as soon as it is released in the relevant Patch Tuesday rollout, and check Microsoft's advisory for the exact affected SKUs and KB articles, since the CVE description does not enumerate version ranges. Because this is a local privilege escalation requiring an existing account, prioritize patching multi-user systems such as RDS/terminal servers, VDI images, and shared workstations where untrusted low-privileged users log on. Until patched, limit local logon rights on sensitive hosts and monitor Windows Audio Service crash or EDR use-after-free telemetry.

Affected
Microsoft Windows (Windows Audio Service)
Estimated exposure
masson the order of 1 billion+ Windows devices (Audio Service runs on essentially all Windows clients) — The Windows Audio Service is present on effectively every Windows client installation, and Microsoft has publicly cited an installed base of well over a billion active Windows devices, so exposure is limited mainly by the unspecified…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.