CVE-2024-30097
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
CVSS
8.8
High
EPSS
1.7%
p75
KEV
—
Exploit Today
22
0-100
Published: Jun 11, 2024 · Last modified: Jul 20, 2026 · CWE-415
1.7%EPSS · 30 days1.7%
2026-06-302026-07-20
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-646217.3 HIG—
——0FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorIds array is allocated through the settings object, and a raw non-owning pointer to it is freed on the strtoul error path without clearing settings->MonitorIds, leaving it dangling; at teardown freerdp_settings_free() frees the same buffer again. An attacker who convinces a victim to open a crafted .rdp file with oversized monitor tokens can trigger a size-controlled double-free in any FreeRDP CLI client (xfreerdp/sdl-freerdp/wlfreerdp) in the default configuration.1dCVE-2026-137136.2 MED3.8%
——1YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack.
In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node stored under that name with syck_free_node. That node can still be live on the parser's value stack, so syck_hdlr_add_node reaches it again and frees it a second time. On a normal build the 48-byte node chunk is freed twice and the interpreter aborts. Anchors need no special flags, so this is reached on the default Load path, and a 7-byte document that redefines an anchor triggers it.
Any caller that runs Load or LoadFile on an untrusted document that redefines an anchor mid-parse crashes the interpreter, a denial of service.4dCVE-2026-551327.8 HIG30.0%
——9Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.5dCVE-2026-506857.5 HIG45.7%
——14Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.6dCVE-2026-503617.8 HIG8.7%
——3Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.20hCVE-2026-550047.8 HIG15.8%
——5Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.6d