Impact
The flaw is an out‑of‑bounds read (CWE‑125) in usbaudio.sys, the driver that services USB audio devices. When triggered, the driver can read memory located outside the intended buffer, potentially revealing sensitive data that resides there. Because the vulnerability is triggered only by a local and physical interaction with a USB audio device, it does not allow remote code execution or full system compromise; the data exposed originates from the host memory.
Affected Systems
The affected systems are a range of Windows client and server releases. Client workstations including Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 24H2, 25H2, 26H1 are vulnerable. Server editions such as Windows Server 2012 (full and core), 2012 R2 (full and core), 2016, 2019 (full and core), 2022 and 2025 (full and core) also contain the flaw.
Risk and Exploitability
The CVSS base score of 4.6 reflects a low severity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of active exploitation. Access requires a physical connection to a USB audio device, limiting the attack surface. Organizations should be aware that the threat is limited to local attackers who physically attach a USB audio device to a vulnerable machine.
OpenCVE Enrichment