Impact
The vulnerability is an out‑of‑bounds read in the Windows USB Audio Class driverusbaudio.sys. An attacker who can connect a USB audio device to a system can trigger the read and extract data from the driver’s memory space, effectively disclosing that information without user interaction. This flaw is a buffer overread (CWE‑125) that does not modify data but exposes sensitive content.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including both standard editions and Server Core installations.
Risk and Exploitability
The CVSS score of 6.8 classifies the vulnerability as moderate, and the EPSS score of less than 1 % indicates a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. The attack requires the attacker to have local physical access to the target machine to connect a USB audio device, which limits the reach to environments where such physical interactions are feasible. There is no documented remote or network exploitation path.
OpenCVE Enrichment