Impact
The vulnerability is a stack‑based buffer overflow in the Windows USB Driver that allows an attacker with authorized network access to elevate privileges. By sending malicious input that overflows a buffer on the stack, the attacker can execute arbitrary code or gain higher authority on the system. The primary impact is a privilege escalation that increases authority on the affected machine. The likely attack vector involves an authorized attacker triggering the overflow through a network session or a malicious USB device; based on the description, it is inferred that the attacker must have some existing user rights or network reach, rather than being fully remote.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025 (including Server Core installations). Both 32‑bit and 64‑bit architectures, as well as ARM64, are impacted across these operating systems.
Risk and Exploitability
The CVSS score of 8 marks this a high‑severity vulnerability. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, indicating that no widely known active exploits have been observed yet. Nevertheless, because the flaw allows privilege escalation over a network within an authorized environment, the risk remains significant, especially in large or critical infrastructures where attackers may already have some foothold. Organizations should treat this with urgency.
OpenCVE Enrichment