Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Windows USB Print Driver contains a race condition that allows an authorized user to trigger a concurrent execution flaw, leading to elevated privileges. The flaw is based on improper synchronization of a shared resource, which can be exploited to bypass access controls (CWE‑362) or cause a use‑after‑free scenario (CWE‑416). The impact is a local privilege escalation that could let a user gain administrative rights on the affected system.

Affected Systems

Microsoft Windows 11 version 24H2, 25H2 and 26H1, as well as Microsoft Windows Server 2025 including Server Core installations are vulnerable. These are the only products specifically listed by the CNA, with no additional affected versions identified.

Risk and Exploitability

The vulnerability has a CVSS score of 7.0 and an EPSS score of less than 1%, indicating low but nonzero likelihood of exploitation. It is not listed in CISA’s KEV catalog. The attack requires a local, authorized user with access to a USB printer device, making distribution outside the host difficult. Based on the description, it is inferred that an attacker can supply a malicious USB printer device to trigger the race condition and gain administrative privileges, potentially compromising confidentiality, integrity, and availability of the host.

Generated by OpenCVE AI on July 31, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the official Microsoft security update that addresses CVE-2026-49802
  • Disable USB printer driver installation for non‑trusted devices or enforce device installation restrictions to block malicious USB printer devices
  • Monitor event logs for USB device activity and review driver update status regularly

Generated by OpenCVE AI on July 31, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Title Windows USB Print Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:54:26.569Z

Reserved: 2026-06-01T17:02:37.208Z

Link: CVE-2026-49802

cve-icon Vulnrichment

Updated: 2026-07-15T10:50:05.519Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:00:07Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free