Impact
Integer overflow or wraparound in the Windows USB Audio Class driver (usbaudio.sys) allows an attacker with local or authorized access to increase their privileges on the affected system. This flaw arises from a numeric boundary error, enabling escalation to higher‑privilege accounts, and is classified as CWE‑190. The vulnerability is specific to a native driver interacting with audio hardware, so it does not compromise network services or remote users directly.
Affected Systems
Affected machines include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and all supported Windows Server releases from 2012 through 2025, including core installations. All listed operating systems run the usbaudio.sys driver, which is impacted by this overflow flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. The likely attack vector is local or authorized access, where an attacker can install or manipulate a USB audio device to trigger the overflow. Because the exploit requires interaction with the physical device, mitigation is achievable by patching before deployment of vulnerable hardware.
OpenCVE Enrichment