ZeroHour

CVE-2026-69394

mass

Heap Buffer Overflow in Windows Audio Service Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69394 is a heap-based buffer overflow (CWE-122) in the Windows Audio Service, a component present on Windows systems by default. Because the attack vector is local (AV:L) and requires low privileges, an attacker must already be able to execute code on the machine as a standard user; the high attack complexity rating means triggering the overflow requires specific conditions, but no user interaction is needed. Successful exploitation allows an authorized local attacker to elevate their privileges on the system, and the high confidentiality/integrity/availability impacts indicate the local account can be escalated to a fully privileged state. Any Windows deployment where untrusted users can run code — shared workstations, laptops, multi-user servers, and VDI hosts — is relevant. There is no known public proof of concept, it is not yet listed in CISA KEV, and the 30-day EPSS of 0.3% (17th percentile) suggests exploitation activity is currently unlikely.

What to do: Apply Microsoft's security update for this CVE as soon as it is available via Windows Update; because no specific fixed build is named in the data, defer to Microsoft's advisory for exact versions. Prioritize systems where local code execution by untrusted users is common (shared desktops, multi-user servers, VDI), since exploitation requires an existing low-privileged foothold. Until patched, restrict which users can run arbitrary code on sensitive hosts and watch for Microsoft exploitation-status updates.

Affected
Microsoft Windows (Windows Audio Service)
Estimated exposure
masson the order of hundreds of millions to ~1.4 billion Windows devices (Windows install base; upper bound, since affected versions are unspecified) — Windows Audio Service is a default component of the Windows desktop OS, which runs on roughly 1.4 billion devices worldwide, though the lack of specified affected versions means this is an upper-bound estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.