Impact
A heap-based buffer overflow in the Windows USB Video Driver can be triggered by a malicious USB device that the operating system accepts as a video source. This overflow allows an attacker who has local access to the machine to read and write arbitrary memory locations, which can be used to gain elevated privileges, effectively escalating from a non-administrative user to a system or administrator level. The vulnerability is identified as CWE-122, indicating a heap-based overflow weakness.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2019, Windows Server 2022, and Windows Server 2025, including both Server Core and full installations. Devices running either 32‑bit or 64‑bit processor architectures may be vulnerable depending on the specific OS build.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high-severity flaw, and while the EPSS score is currently not available, the lack of a KEV listing does not diminish the potential damage; an attacker with local physical or remote access who can supply a crafted USB video device can exploit the overflow. Because the attack requires an authorized local presence, the risk is confined to environments where USB devices are accepted without strict validation. Prompt deployment of the vendor-provided patch will prevent privilege escalation, whereas failure to do so leaves systems susceptible to gaining administrative rights.
OpenCVE Enrichment