Impact
The vulnerability is a heap‑based buffer overflow in the Windows USB Audio Class driver (usbaudio.sys). An attacker who is authorized on the local system can supply crafted data that overflows a heap buffer, allowing the attacker to gain higher privileges. The weakness is a classic out‑of‑bounds write that can corrupt control data and potentially lead to arbitrary code execution with elevated rights, compromising the confidentiality, integrity, and availability of the system.
Affected Systems
Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2; Windows 11 Versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations). All affected builds on x86, x64, and ARM64 architectures are listed in the Common Platform Enumeration record.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity local privilege escalation. No EPSS score is publicly available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no publicly known exploit yet. The attack vector is local; an attacker must be able to run code or influence the driver on the target machine. Nevertheless, the lack of a publicly available exploit does not diminish the risk to systems where the driver remains unpatched, especially in environments that allow USB audio devices.
OpenCVE Enrichment