Impact
The vulnerability is a use‑after‑free flaw in the Windows USB Audio Class driver, usbaudio.sys, that allows an attacker to execute privileged code on the local machine. By triggering the freed memory usage, an attacker can gain elevated rights, enabling further malicious activity such as installing malware, modifying system settings, or accessing sensitive data. The flaw is specifically a use‑after‑free error identified as CWE‑416, which typically permits exploitation when attacker‑controlled data is used after the memory has been freed.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2016, 2019, 2022, and 2025, including Server Core installations. All affected systems run the usbaudio.sys driver that provides USB audio device support.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, although the EPSS score is not available, so the likelihood of exploitation is unknown but can be considered moderate to high in environments where USB audio devices are allowed. The issue is not listed in the CISA KEV catalog, yet the use‑after‑free nature and local privilege escalation potential suggest an authorized attacker who can supply a malicious USB audio device can adapt the driver to gain elevated privileges. The attack vector is inferred to be local, requiring access to USB ports and administrative user rights on the affected machines.
OpenCVE Enrichment