Impact
An integer overflow or wraparound flaw in the Windows USB Audio Class driver (usbaudio.sys) allows an attacker that has physical access to a computer to gain higher privileges. The vulnerability is triggered when the driver processes certain USB audio messages, causing a corrupted length field to be interpreted as a larger value than intended. This computation error can overwrite protected memory and grants the attacker local privilege escalation, potentially turning a standard user into an administrator or higher. The weakness exists in the driver’s parsing logic and is classified as CWE-122 and CWE-190. The impact is that an attacker can execute arbitrary code with elevated rights, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2019, Windows Server 2022, and Windows Server 2025. These releases include the vulnerable usbaudio.sys driver.
Risk and Exploitability
The CVSS base score of 6.6 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a physical USB connection; an attacker must have physical access to inject malicious USB audio traffic. Once the overflow is triggered, the attacker can achieve privilege escalation on the local system. Because the flaw is in a kernel driver, exploitation is nontrivial but feasible for an attacker with hardware access and knowledge of USB audio protocols. The risk depends on the presence of untrusted USB devices on the network. As a result, the vulnerability poses a moderate but tangible risk to systems that allow arbitrary USB device attachment.
OpenCVE Enrichment