Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a race condition in the Windows USB Print Driver caused by improper synchronization of a shared resource. An authorized local user who can trigger concurrent operations against the driver may manipulate privileged actions, allowing them to elevate privileges on the affected system. This weakness is identified as CWE‑362 and CWE‑416.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025—including Server Core installations—are impacted. Versions 24H2 and 25H2 are available only for arm64, while 26H1 is available only for x64. The listed CPE entries confirm these builds.

Risk and Exploitability

The CVSS score of 7 indicates a high severity, but the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local attacker with authorized access to a system running the affected driver and relies on a timing attack that triggers the race condition. Remote exploitation is not described. Mitigation thus focuses on applying the vendor patch and limiting USB printing activity to reduce exposure.

Generated by OpenCVE AI on August 3, 2026 at 03:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or cumulative update for the affected Windows 11 and Windows Server 2025 editions.
  • Enable automatic updates so the fix for the USB print driver is downloaded and installed.
  • If patch deployment is delayed, disable or remove legacy USB printing drivers, or restrict USB printing through Group Policy to prevent the race condition from being exercised.

Generated by OpenCVE AI on August 3, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Title Windows USB Print Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:54:27.117Z

Reserved: 2026-06-01T17:02:37.208Z

Link: CVE-2026-49806

cve-icon Vulnrichment

Updated: 2026-07-14T17:25:29.643Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:30:13Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free