Description
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
Published: 2026-07-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Windows USB Print with physical access to a machine’s USB port. The flaw enables the attacker to execute code in kernel mode, thereby elevating privileges to SYSTEM level. This type of flaw is classified as CWE‑416: Use After Free.

Affected Systems

Affected are all Microsoft Windows 11 releases 24H2, 25 as well as Windows Server 2025 (both full and Server Core). Both arm64 and x64 builds of the 26H1 client and the Server Core images are listed in the CPE entries. The advisory does not state any mitigations beyond the patch, and the issue is limited to USB print devices.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate risk, and the EPSS score of less than 1% suggests that current exploitation likelihood is very low. Because the flaw requires an attacker to physically connect a USB device, the attack surface is limited to premises that allow such access. Although the vulnerability is not in the CISA KEV catalog, organizations with high exposure should still prioritize the update.

Generated by OpenCVE AI on July 31, 2026 at 09:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Windows security update that addresses CVE‑2026‑55000 as published by Microsoft.
  • Restrict access to USB ports on endpoints, using hardware or software port blockers, to eliminate the opportunity for a physical USB device to be attached.
  • Enforce a comprehensive device control policy and audit USB usage to ensure only approved devices can be connected.

Generated by OpenCVE AI on July 31, 2026 at 09:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
Title Windows USB Print Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:09.489Z

Reserved: 2026-06-16T14:10:05.869Z

Link: CVE-2026-55000

cve-icon Vulnrichment

Updated: 2026-07-14T17:44:45.491Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:45:04Z

Weaknesses