Impact
The vulnerability is an out-of-bounds read in the Windows USB Hub Driver that can expose memory beyond the intended bounds (CWE-125). This flaw can be leveraged by an attacker with physical access to elevate privileges on the affected system, potentially allowing compromise of the entire machine and its data. It does not provide remote code execution but enables local privilege escalation through the USB subsystem.
Affected Systems
The flaw is present in Microsoft Windows 10 (Version 1607, 1809, 21H2, 22H2) and Windows 11 (Versions 23H2, 24H2, 25H2, 26H1) as well as Windows Server 2016, 2019, 2022, and 2025, including Server Core installations across x86, x64, and arm64 architectures. All builds listed in the vendor product list are susceptible to the issue.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and no EPSS value is publicly available. The vulnerability is not listed in the CISA KEV catalog and appears to be a local (physical) attack vector, requiring direct access to the USB hub and interaction with the driver. No widespread exploitation tools have been disclosed, but the potential for local privilege escalation remains significant, warranting prompt action.
OpenCVE Enrichment