Impact
The Windows USB Print Driver contains a race condition that allows an authorized user to trigger a concurrent execution flaw, leading to elevated privileges. The flaw is based on improper synchronization of a shared resource, which can be exploited to bypass access controls (CWE‑362) or cause a use‑after‑free scenario (CWE‑416). The impact is a local privilege escalation that could let a user gain administrative rights on the affected system.
Affected Systems
Microsoft Windows 11 version 24H2, 25H2 and 26H1, as well as Microsoft Windows Server 2025 including Server Core installations are vulnerable. These are the only products specifically listed by the CNA, with no additional affected versions identified.
Risk and Exploitability
The vulnerability has a CVSS score of 7.0 and an EPSS score of less than 1%, indicating low but nonzero likelihood of exploitation. It is not listed in CISA’s KEV catalog. The attack requires a local, authorized user with access to a USB printer device, making distribution outside the host difficult. Based on the description, it is inferred that an attacker can supply a malicious USB printer device to trigger the race condition and gain administrative privileges, potentially compromising confidentiality, integrity, and availability of the host.
OpenCVE Enrichment