Impact
The vulnerability is a heap-based buffer overflow in the Windows USB Audio Class driver (usbaudio.sys). This flaw enables an authorized local attacker to gain elevated privileges, potentially allowing full control of the affected system. The weakness is classified as CWE‑122.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 versions 23H2, 24H2, 25H2, and 26H1. In addition, Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both standard and Server Core installations) are impacted. The driver is delivered as part of the standard Windows installation and is active on systems that support USB audio devices.
Risk and Exploitability
The attack requires a local privileged user who can run malicious code that triggers the overflow through a USB audio device. An attacker must have physical or remote access sufficient to provision such a device. The lack of an EPSS score means no publicly available exploitation data, but the CVSS score of 7.8 indicates high severity. Since the vulnerability is not yet listed in CISA’s KEV catalog, widespread exploitation is not documented, yet the high impact warrants urgent patching.
OpenCVE Enrichment