Description
A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. To exploit the vulnerability, an attacker would need to convince a user to open a specially crafted document containing TTS content invoked through a scripting language. The update address the vulnerability by modifying how the system handles objects in memory.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Physical
RL
O
RC
Changed
Affected products
- Microsoft / Windows 76.1.0 – publication
- Microsoft / Windows 7 Service Pack 16.1.0 – publication
- Microsoft / Windows Server 2008 R2 Service Pack 16.1.7601.0 – publication
- Microsoft / Windows Server 2008 R2 Service Pack 1 (Server Core installation)6.1.7601.0 – publication
- Microsoft / Windows Server 2008 R2 Systems Service Pack 16.1.0 – publication