1. Microsoft Windows Vista comes with voice recognition installed and
active by default.
2. Voice services has tons of security privileges, since it is a
"local" service and therefore safe, right?
3. Playing a sound through the speakers on Vista requires almost no
security privileges, since that's a harmless operation, right?
4. By playing a prerecorded file of spoken commands, an unprivileged
process can execute arbitrary processes that get executed with
elevated security privileges.
http://isc.sans.org/diary.html?storyid=2148