Impact
A race condition and improper synchronization in the Windows USB Video Driver enable an attacker who controls a USB video device to elevate privileges locally. The flaw allows concurrent operations on a shared resource without proper locking, triggering a use‑after‑free that can be leveraged to execute arbitrary code with higher privileges. The weakness is a classic race‑condition (CWE‑362) combined with a use‑after‑free (CWE‑416).
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019 (including Server Core), 2022, and 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7 indicates moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local; an attacker needs physical access to the system and the ability to insert a malicious USB video device. Privileges can be escalated to run arbitrary code, potentially compromising the entire system. Given the lack of documented network exploitation and the moderate CVSS, the risk is considered moderate, but prompt remediation is advised.
OpenCVE Enrichment