Impact
The vulnerability is a time‑of‑check time‑of‑use race condition in the Windows USB Audio Class driver (usbaudio.sys). By triggering this race condition an authorized local user can gain higher privileges, allowing the attacker to perform administrative actions on the system. This flaw is related to integer underflow/overflow (CWE‑191) and race conditions (CWE‑367), compromising driver integrity.
Affected Systems
Affected products include Microsoft Windows 10 versions from 1607 through 22H2 and Windows 11 versions 23H2, 24H2, 25H2, and 26H1. The same flaw exists on Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, and Windows Server 2022/2025, in both standard and Server Core installations. Administrators should verify that these systems have not yet applied the relevant Microsoft update.
Risk and Exploitability
The CVSS score of 7.0 indicates medium‑to‑high severity, while the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires a local, authenticated user, the attack vector is primarily confined to local machines; however, a malicious USB audio device or driver could be used to trigger the race condition automatically. Upon successful exploitation, the attacker could gain administrative privileges, enabling system compromise, data tampering, or the installation of further malware.
OpenCVE Enrichment