Impact
A heap‑based buffer overflow exists in the Windows USB Mass Storage Class Driver. An attacker who can send specially crafted USB data over a network can trigger the overflow, allowing arbitrary code to execute with the privileges of the local user or the system. This flaw can be used to compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score is not available, indicating uncertainty of exploitation probability. The vulnerability is not listed in the CISA KEV catalog. According to the description, the attack requires an attacker to send malicious data through the USB Mass Storage Class driver over a network, suggesting that the vector may involve either a malicious USB device connected to the victim or a network‑based USB access mechanism. The ability to execute arbitrary code remotely poses a high risk if the threat actor can reach the target system.
OpenCVE Enrichment