Description
Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug in the Windows USB Video Driver enables an authorized local attacker to elevate privileges, potentially gaining admin privileges on the host. This flaw allows the attacker to execute arbitrary code after the driver frees memory, a classic example of a memory‑management vulnerability categorized as CWE‑416.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation, are affected. The 24H2 and 25H2 releases target ARM64 platforms, while version 26H1 addresses x64 architectures.

Risk and Exploitability

The CVSS score of 7.0 classifies this as a high‑severity vulnerability. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, indicating a lack of confirmed widespread exploitation. The attack model requires the attacker to have local, authorized access to plug a USB video device and to deliver exploit code that triggers the use‑after‑free condition.

Generated by OpenCVE AI on September 8, 2026 at 21:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for CVE-2026-69422 from the Microsoft Security Response Center (MSRC) update guide.
  • Restrict or disable unnecessary USB video device drivers to limit attack surface.
  • Continuously apply cumulative Windows updates to ensure related fixes are received and to maintain overall system integrity.

Generated by OpenCVE AI on September 8, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
Title Windows USB Video Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:38:34.722Z

Reserved: 2026-08-03T20:59:32.783Z

Link: CVE-2026-69422

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:05.433

Modified: 2026-09-08T19:22:18.470

Link: CVE-2026-69422

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:15:13Z

Weaknesses