ZeroHour

CVE-2026-69444

mass

Heap-Based Buffer Overflow in Microsoft Windows Speech Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-69444 is a heap-based buffer overflow (CWE-122) in the Windows Speech component of Microsoft Windows. An attacker who already has authorized access to a system — a local user with limited privileges — can trigger the overflow through the vulnerable Speech component, and the CVSS vector (AV:L/PR:L/UI:N) indicates no user interaction and no special conditions are needed. Successful exploitation lets the attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability on the compromised machine. Any Microsoft Windows installation running the affected Speech component is exposed, although Microsoft has not published specific affected version ranges in the available data. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.3% chance of exploitation within 30 days, indicating low near-term exploitation risk.

What to do: Apply Microsoft's security update for CVE-2026-69444 via Windows Update on all Windows systems, prioritizing shared and multi-user hosts (e.g., RDS servers, kiosks, shared workstations) where untrusted local users are most likely. As an interim mitigation, restrict execution of untrusted local code, and verify remediation by confirming the update in installed update history.

Affected
Microsoft Windows Speech (component of Microsoft Windows)
Estimated exposure
mass≈1 billion+ Windows installations (Speech is a standard Windows OS component; affected ranges unpublished) — Windows runs on more than one billion active devices and the Speech component ships as a standard part of the OS, so plausibly affected deployments are on the order of hundreds of millions to over a billion systems, though Microsoft has…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.