Impact
This vulnerability is an out‑of‑bounds read in a Windows USB driver that can be triggered by an attacker with local access. By exploiting the flaw, a malicious user can elevate privileges to the level of the operating system, potentially gaining administrative or system‑level access. The weakness is identified as an improper bounds check and an arbitrary input error. This elevation capability compromises confidentiality, integrity, and availability of the affected system.
Affected Systems
The flaw affects multiple Microsoft Windows families, including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and several Windows Server releases from 2012 R2 through 2025. All listed builds, across x86, x64, arm64, and Server Core implementations, are impacted.
Risk and Exploitability
The risk is moderate to high, reflected by a CVSS score of 7.8, and the EPSS score is not available, indicating insufficient data on exploitation frequency. The vulnerability is not currently listed in CISA's KEV catalog. The attack vector is inferred to be local; an attacker must be able to insert a USB device or otherwise interact with the driver while authorized. Because it requires only local control, any user with physical or remote local access could exploit it, making the risk significant for environments where USB device use is widespread.
OpenCVE Enrichment