ZeroHour

CVE-2026-69604

mass

Heap Buffer Overflow in Windows Audio Service Enables Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69604 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Audio Service, a core component of the Windows operating system. An attacker who already has limited authorized access on a local machine (low-privilege local account, no user interaction required) can trigger the overflow through interactions with the audio service. Successful exploitation allows the attacker to elevate privileges locally, with high impact on confidentiality, integrity, and availability per the CVSS score of 7.8. All Windows systems running an affected version of the audio service component are exposed to this risk, though exploitation requires prior local access rather than remote reachability. As of this analysis, there is no known public proof-of-concept, the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Deploy Microsoft's security update addressing CVE-2026-69604 as soon as it becomes available via Windows Update, prioritizing multi-user hosts, shared workstations, and systems where low-privilege local accounts are less trusted. Because the flaw is local-only, there is no network-based mitigation; verify affected builds and fixed versions directly in Microsoft's advisory. Routine endpoint patching cadence is adequate given the absence of known exploitation and low EPSS.

Affected
Microsoft Windows (Windows Audio Service)
Estimated exposure
mass≈1 billion+ Windows endpoints potentially affected (the audio service ships by default with Windows) — The Windows Audio Service is a default component on essentially all Windows client and server installations, and the Windows installed base is commonly estimated at over a billion devices, though only the builds listed in Microsoft's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.