ZeroHour

CVE-2026-69447

mass

Heap buffer overflow in Windows Audio Service enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-69447 is a heap-based buffer overflow (CWE-122) in the Windows Audio Service, a core component of Microsoft Windows. An authorized attacker — meaning a user who already has a local account or a foothold on the machine — can trigger the flaw by sending crafted input to the service, overrunning a heap buffer. Successful exploitation allows the attacker to execute code with the service's privileges, elevating from a low-privileged local user to higher privileges on the system (typically SYSTEM), with high impact on confidentiality, integrity, and availability consistent with the 7.8 CVSS score. Any Windows installation running the vulnerable Audio Service is affected; the provided data does not specify exact Windows version ranges. No in-the-wild exploitation is currently known: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% chance of exploitation within 30 days (27th percentile).

What to do: Apply the Windows security update addressing CVE-2026-69447 via Windows Update or your enterprise patch channel (WSUS/Intune/SCCM) as soon as Microsoft's advisory identifies the release; the provided data does not list specific fixed builds or workarounds. In the meantime, prioritize patching hosts where untrusted or low-privileged users can sign in locally or via Remote Desktop, since local access is a prerequisite for exploitation. After deployment, verify patch uptake with vulnerability scans using updated detection signatures.

Affected
Microsoft Windows (Windows Audio Service)
Estimated exposure
mass≈1 billion+ Windows installations — The Windows Audio Service is a default component on essentially every Windows client and server installation, and Microsoft has publicly reported over 1 billion active Windows devices, though practical exploitability is limited to systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.