Impact
The vulnerability is a heap‑based buffer overflow in the Windows USB Video Driver. If an attacker can supply malformed data to the driver—likely through network traffic or a malicious USB video device—an overflow can corrupt heap memory and cause the driver to execute arbitrary code with elevated privileges. The flaw is classified as CWE‑122, meaning the driver does not properly validate or handle heap allocations, enabling an attacker to change the program’s execution flow.
Affected Systems
Affected systems include Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and server core installations. All these versions use the Windows USB Video Driver component referenced in the vendor product list.
Risk and Exploitability
The CVSS base score for this issue is 8, indicating high severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation is presently low or unverified. However, the flaw requires an attacker who can send crafted data to the driver, which could be achieved over a network connection or by connecting a malicious USB video device. Once the overflow is triggered, privilege escalation to system or administrative rights can occur, posing a significant risk to affected systems.
OpenCVE Enrichment