ZeroHour

CVE-2026-70562

mass

Double Free in Microsoft Windows Audio Service Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-70562 is a double free (CWE-415) memory-safety vulnerability in the Windows Audio Service, a core component of Microsoft Windows. The flaw is triggered when the service releases the same memory allocation twice during local operations, and the high complexity score in the CVSS vector suggests a timing- or state-dependent condition rather than straightforward triggering. An attacker who already holds valid, low-privileged local access to a system can exploit it to elevate privileges locally, gaining full high-integrity execution on that host with no user interaction required. Any Windows installation running an affected version of the audio service is in scope, though the specific affected Windows builds are not enumerated in the source data. There is currently no known public proof-of-concept, no entry in CISA's KEV catalog, and a low EPSS score (0.3% probability of exploitation within 30 days), indicating no observed exploitation activity to date.

What to do: Apply Microsoft's security update for this CVE as soon as it is available, and check the official Microsoft advisory for the exact affected builds since version ranges are not specified in this data. In the meantime, prioritize patching systems where multiple low-privileged users can sign in or where local access is broadly available (RDP hosts, VDI, shared workstations), as those present the most practical privilege-escalation risk. With no public PoC, no KEV listing, and low EPSS, this is a routine patch-cycle item rather than an emergency.

Affected
Microsoft Windows (Windows Audio Service)
Estimated exposure
mass≈1 billion+ Windows devices as the upper bound (audio service is a core OS component present on virtually all Windows client installations) — The Windows Audio Service ships with every Windows client installation and the Windows desktop installed base exceeds 1 billion devices, so potential exposure is effectively the entire Windows fleet, though practical risk is limited to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.