Impact
An out‑of‑bounds read in the Windows USB Audio Class driver (usbaudio.sys) allows an attacker with local, authorized access to read sensitive data from memory. The flaw is caused by improper bounds checking and input validation, matching CWE‑125 and CWE‑20. While it does not enable code execution, it can expose confidential information such as credentials or cryptographic material that the driver has in memory.
Affected Systems
Microsoft Windows 10 (builds 1607, 1809, 21H2, 22H2), Windows 11 (builds 23H2, 24H2, 25H2, 26H1), and Windows Server 2012 through 2025—including Server Core installations—run with the default USB Audio Class driver and are susceptible to the vulnerability.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the EPSS score is not available, leaving the likelihood of exploitation uncertain. The attack requires a local, authorized user, so it is a local attack vector rather than a remote one. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation yet, but it constitutes a potential source of data leakage that could aid further attacks if sensitive data is accessed.
OpenCVE Enrichment