Impact
The vulnerability is a heap‑based buffer overflow (CWE-122) that occurs within the Windows USB Video Driver. When a malicious USB video device is connected, the driver incorrectly handles data, writing beyond the bounds of a heap buffer and allowing an unauthorized attacker to elevate privileges on the affected system.
Affected Systems
Affected by Microsoft are Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2 and 25H2; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including all Server Core installations. The vulnerability impacts 32‑bit, 64‑bit and ARM64 variants as identified in the CPE data.
Risk and Exploitability
The CVSS score of 6.6 indicates a moderate impact, and the EPSS score of less than 1 % signifies a very low estimated exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a physical attacker to connect a malicious USB video device; it is not a remote network threat.
OpenCVE Enrichment