Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a race condition in the Windows USB Print Driver that allows an authorized local user to execute concurrent operations on a shared resource without proper synchronization. By carefully timing two print tasks, the attacker can trigger an improper state in the driver that results in privilege escalation. The vulnerability is classified as CWE-362 race condition and CWE-125 out‑of‑bounds read, but the description does not provide evidence of an out‑of‑bounds read occurring. The primary consequence is that a user with local rights can gain higher privileges on the affected system.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, 26H1 and Microsoft Windows Server 2025, including Server Core installations, are affected. The flaw is present in the USB print service across both ARM64 and x64 architectures as indicated by the CPE strings.

Risk and Exploitability

The CVSS score of 7 denotes high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local, authenticated user, who must orchestrate a precisely timed sequence of print operations to trigger the race condition. The attack surface is limited to systems that use the vulnerable USB print driver and have remote or local administrative access.

Generated by OpenCVE AI on July 31, 2026 at 09:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft cumulative update that contains the fix for CVE‑2026‑54111.
  • Restart the affected system to ensure the updated USB print driver is loaded.
  • If USB printing is not needed, disable the USB print service to reduce the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Title Universal Print Management Service Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-125
CWE-362
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:25.615Z

Reserved: 2026-06-11T20:33:37.835Z

Link: CVE-2026-54111

cve-icon Vulnrichment

Updated: 2026-07-14T17:44:47.505Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:45:04Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')