Impact
An out‑of‑bounds read in the Windows USB Audio Class driver (usbaudio.sys) allows an attacker to read memory that should not be accessible, resulting in disclosure of sensitive data. The flaw does not provide direct code execution but leaks information that could aid in further attacks or compromise privacy of the victim. The vulnerability originates from a buffer over‑read identified as CWE-125.
Affected Systems
Microsoft Windows 10 releases from version 1607 through 22H2, Windows 11 releases from 24H2 through 26H1, and Windows Server editions from 2012 up to 2025, including Server Core installations. All affected installations rely on the usbaudio.sys component and are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The likely attack vector is local physical, based on the description that the flaw requires a physical presence to attach a USB audio device. The vulnerability is not listed in the CISA KEV catalog, but any system that permits untrusted USB devices presents an attack surface. Organizations should consider the overall risk and treat the flaw as a potential data privacy issue.
OpenCVE Enrichment