Impact
The vulnerability is a use‑after‑free in the Windows USB Print with physical access to a machine’s USB port. The flaw enables the attacker to execute code in kernel mode, thereby elevating privileges to SYSTEM level. This type of flaw is classified as CWE‑416: Use After Free.
Affected Systems
Affected are all Microsoft Windows 11 releases 24H2, 25 as well as Windows Server 2025 (both full and Server Core). Both arm64 and x64 builds of the 26H1 client and the Server Core images are listed in the CPE entries. The advisory does not state any mitigations beyond the patch, and the issue is limited to USB print devices.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk, and the EPSS score of less than 1% suggests that current exploitation likelihood is very low. Because the flaw requires an attacker to physically connect a USB device, the attack surface is limited to premises that allow such access. Although the vulnerability is not in the CISA KEV catalog, organizations with high exposure should still prioritize the update.
OpenCVE Enrichment