CVE-2026-32089 is a use-after-free vulnerability in the Windows Speech Brokered API that permits authorized local users to escalate their privileges on affected Windows systems. The vulnerability resides in memory management within the Speech Brokered API component, which is a core Windows service. The vulnerability presents HIGH severity with a CVSS score of 7.8, reflecting a local attack vector with low complexity and no user interaction required. An attacker with low privileges can exploit this flaw to gain high-level access, compromising confidentiality, integrity, and availability of the system. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is listed as inactive on threat tracking lists. The EPSS probability of exploitation is extremely low at 0.00044, and the FAUCET risk score of 39.0 indicates moderate concern. Community attention and public exploit code availability appear limited at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.9060CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.8644CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.7184CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.