CVE-2026-70562
massDouble Free in Microsoft Windows Audio Service Enables Local Privilege Escalation
CVE-2026-70562 is a double free (CWE-415) memory-safety vulnerability in the Windows Audio Service, a core component of Microsoft Windows. The flaw is triggered when the service releases the same memory allocation twice during local operations, and the high complexity score in the CVSS vector suggests a timing- or state-dependent condition rather than straightforward triggering. An attacker who already holds valid, low-privileged local access to a system can exploit it to elevate privileges locally, gaining full high-integrity execution on that host with no user interaction required. Any Windows installation running an affected version of the audio service is in scope, though the specific affected Windows builds are not enumerated in the source data. There is currently no known public proof-of-concept, no entry in CISA's KEV catalog, and a low EPSS score (0.3% probability of exploitation within 30 days), indicating no observed exploitation activity to date.
What to do: Apply Microsoft's security update for this CVE as soon as it is available, and check the official Microsoft advisory for the exact affected builds since version ranges are not specified in this data. In the meantime, prioritize patching systems where multiple low-privileged users can sign in or where local access is broadly available (RDP hosts, VDI, shared workstations), as those present the most practical privilege-escalation risk. With no public PoC, no KEV listing, and low EPSS, this is a routine patch-cycle item rather than an emergency.
| Microsoft Windows (Windows Audio Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.