Impact
Windows USB Driver contains a race condition that arises from improper synchronization of a shared resource. The flaw can be triggered by an authorized local user, allowing that user to elevate privileges on the affected system. The weakness is identified as a race condition (CWE‑362) and may also exhibit a use‑after‑free behavior (CWE‑416).
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability that can be exploited locally. EPSS data is not available; the issue is not listed in the CISA KEV catalog. Exploitation would require an attacker with local access who can manipulate USB device interactions to trigger the race condition. Given the local nature and the lack of network or authentication prerequisites, the primary risk is privilege escalation on compromised or physically accessible workstations. The overall risk remains moderate to high until the relevant Microsoft security update is applied.
OpenCVE Enrichment