Impact
The vulnerability is a buffer over-read (CWE-125) in the Windows USB Mass Storage Class driver. An attacker with physical access can deliver malformed USB requests that cause the driver to read memory beyond intended bounds, potentially exposing sensitive data or enabling jump‑to‑code that elevates privileges and compromises system confidentiality, integrity, or availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, together with Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 installations are affected. All 32‑bit, 64‑bit, ARM64 variants listed in the CNA entries are vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The flaw’s type—buffer over-read (CWE-125)—may allow local attackers who can attach a crafted USB device to read beyond intended bounds, potentially leading to privilege escalation. EPSS data is unavailable, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, and because it requires physical USB access, it is limited to local attackers but still poses a significant risk to environments that allow unrestricted USB usage.
OpenCVE Enrichment