Impact
The Windows USB Video Driver contains an integer overflow or wraparound flaw that can be triggered by an authorized local attacker. This flaw allows the attacker to gain higher privileges on the affected system. The weakness falls under CWE-190.
Affected Systems
This vulnerability impacts multiple Windows releases, including Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, covering both standard and server core installations. All affected editions run the USB Video Driver that can be exploited.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. Because the EPSS score is not available, the current exploitation probability is unclear, and the vulnerability is not yet listed in CISA’s KEV catalog. The flaw requires local access; the attacker must be authorized on the machine and trigger the overflow via the USB Video Driver, making it a local privilege escalation.
OpenCVE Enrichment