ZeroHour

CVE-2026-69801

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows Audio Service

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69801 is a heap-based buffer overflow (CWE-122) in the Windows Audio Service, a core component of Microsoft Windows. An attacker who already has authorized low-privilege access to a local machine can trigger the flaw without user interaction, causing memory corruption in the audio service. Successful exploitation allows the attacker to elevate privileges locally, gaining higher privileges on the compromised host, which can then be chained with other access for broader compromise. Because the Windows Audio Service is enabled by default, essentially any Windows system is affected; the affected version ranges are not specified in the available data and must be confirmed in Microsoft's advisory. There is no known public proof-of-concept, it is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Monitor Microsoft's security advisory for CVE-2026-69801 to identify the affected Windows versions, then deploy the corresponding security update through Windows Update or WSUS when available. Prioritize patching systems where untrusted or low-privilege users can log on locally or via RDS/VDI, since local privilege escalation is most valuable there. As an interim mitigation, restrict local logon rights to trusted accounts; verify remediation by confirming installed builds against the advisory rather than relying on the service alone.

Affected
Microsoft Windows (Windows Audio Service)
Estimated exposure
mass≈1 billion+ Windows installations (Audio Service is a default, always-present core service) — The Windows Audio Service ships enabled by default on virtually every Windows desktop and server, and Windows' installed base is on the order of a billion-plus devices, so potential exposure is effectively the whole Windows fleet even…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.