ZeroHour

CVE-2026-69540

mass

Use-After-Free Local Privilege Escalation in Windows Audio Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69540 is a use-after-free memory corruption flaw (CWE-416) in the Windows Audio Service, a core component of the Windows operating system. A user who already has limited, authorized access to the local machine can trigger the flaw; the high attack complexity (CVSS AC:H) suggests exploitation may be timing- or state-dependent, but no user interaction is required. Successful exploitation allows the attacker to elevate privileges on the local machine, which is most valuable as a second stage after initial code execution or on shared systems where local users are less trusted. All Windows installations ship the audio service, but the specific affected Windows versions are not listed in the available data and should be confirmed from Microsoft's advisory. As of this writing there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.3% probability of exploitation in the next 30 days, so no exploitation is known.

What to do: Consult Microsoft's security advisory for the affected Windows builds and apply the corresponding Windows security update (cumulative update via Windows Update) as soon as it is available. Until patched, prioritize systems where multiple or untrusted local users can log on — such as RDS/VDI hosts and shared workstations — because exploitation requires an authorized local user. After patching, confirm the update containing the audio service fix is installed.

Affected
Microsoft Windows (Audio Service)
Estimated exposure
mass≈1 billion+ Windows devices (audio service is a core component of the Windows installed base) — The Windows Audio Service is present on essentially every Windows client installation and Microsoft's Windows installed base is on the order of a billion-plus active devices, though actual exposure depends on which releases Microsoft lists…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.