ZeroHour

CVE-2026-69692

mass

Use-after-free in Windows Audio Service enables local privilege escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69692 is a use-after-free (CWE-416) memory-corruption flaw in the Windows Audio Service, a core component that ships with Microsoft Windows. An attacker who already has a low-privileged foothold on a machine (for example via malware or a compromised local account) can trigger the flaw through local interaction with the audio service; the high attack-complexity score (AC:H) suggests timing or race-condition dependent triggering, with no user interaction required. Successful exploitation lets the attacker elevate from user-level to higher local privileges, with high impact to confidentiality, integrity, and availability on the host. Any Windows installation running affected builds is affected; the source data does not enumerate specific Windows versions, so defenders should consult the Microsoft (MSRC) advisory for the exact build list. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Apply Microsoft's security update addressing CVE-2026-69692 when released, checking the MSRC advisory to identify which Windows client and Server builds are included; as a local-only flaw it is not remotely exploitable, so prioritize multi-user and shared hosts (RDS servers, kiosks, developer workstations) where untrusted local code runs. Until patched, least-privilege controls and EDR coverage on Windows endpoints reduce the practical impact of this escalation being chained with malware or account compromise.

Affected
Microsoft Windows (Windows Audio Service)Affected builds not enumerated in the provided data; see the Microsoft (MSRC) advisory for the exact Windows client and Server versions
Estimated exposure
mass>1 billion Windows devices (the Audio Service is a default component of Windows client and Server installs) — The Windows Audio Service is present by default on effectively every Windows installation, and Microsoft's published figure of 1.4+ billion monthly active Windows devices puts the theoretical affected base at the billion-device order.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.