CVE-2026-34328: Windows Audio Service Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
Other sources
Windows Audio Service Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7376Patch KB5099414 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9020Patch KB5099538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5386Patch KB5099540
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34328?
The severity of CVE-2026-34328 is rated medium with a score of 5.5.
What type of vulnerability is CVE-2026-34328?
CVE-2026-34328 is an information disclosure vulnerability in the Windows Audio Service.
How do I fix CVE-2026-34328?
To fix CVE-2026-34328, apply the available patch from Microsoft.
Which systems are affected by CVE-2026-34328?
CVE-2026-34328 affects Microsoft Windows 10, Windows 11, and several versions of Windows Server.
What are the potential risks of CVE-2026-34328?
The potential risks of CVE-2026-34328 include unauthorized disclosure of sensitive information to an attacker.