Impact
This vulnerability is a heap-based buffer overflow in the Windows USB Driver. An attacker who is already authorised to run processes locally can trigger the overflow to obtain higher privileges. The flaw stems from insufficient bounds checking when handling USB data, allowing an attacker to overwrite heap memory and ultimately take control of the system.
Affected Systems
Affected systems include Microsoft Windows 10 21H2 and 22H2, Microsoft Windows 11 23H2, 24H2, 25H2 and 26H1, as well as Microsoft Windows Server 2022 and Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The CVSS base score of 7.8 indicates moderate to high severity. EPSS data is unavailable, so current exploitation probability cannot be quantified at this time. The flaw is not listed in the CISA KEV catalog. Because an attacker must be present on the machine and already have local authorisation, the attack vector is a local privilege escalation, and the vulnerability cannot be abused remotely by an unauthorised attacker.
OpenCVE Enrichment