Impact
An integer underflow flaw in Windows USB Audio Class driver (usbaudio.sys) allows an authorized local user to inject crafted input that causes the driver to work around an arithmetic wrap. This wrap permits the attacker to gain higher privileges, effectively elevating local privileges on the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 and their Server Core installations are listed as affected by the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available and the vulnerability is not yet listed in CISA KEV, suggesting it may not yet be widely exploited. The likely attack vector is local, requiring the attacker to be authenticated or have legitimate access to the machine and an USB audio device that can send crafted data to trigger the underflow. Once triggered, the driver’s privilege escalation could allow the attacker to execute arbitrary code as SYSTEM, affecting confidentiality, integrity, and availability of the entire operating environment.
OpenCVE Enrichment