CVE-2026-68839
massHeap-Based Buffer Overflow RCE in Windows USB Mass Storage Class Driver
CVE-2026-68839 is a heap-based buffer overflow (CWE-122, following CWE-20 improper input validation) in the Microsoft Windows USB Mass Storage Class Driver, an in-box component that handles USB mass-storage devices. Microsoft, the assigning CNA, rates it 9.8 CRITICAL with a network attack vector (AV:N/AC:L/PR:N/UI:N), stating that an unauthorized attacker can execute code over a network without privileges or user interaction; the precise trigger sequence and affected build ranges are not detailed in the available data. Successful exploitation yields high impact to confidentiality, integrity, and availability, i.e., arbitrary code execution and potential full compromise of the affected host. Any Windows system carrying this driver is in scope, which effectively means broadly deployed Windows desktop and server installations, pending Microsoft's enumerated version ranges. Exploitation is not currently known: the flaw is not in CISA KEV, no public proof-of-concept is available, and EPSS assigns only a ~0.8% probability of exploitation within 30 days (54th percentile).
What to do: Apply Microsoft's security update for CVE-2026-68839 across all supported Windows releases as soon as it is available, and check Microsoft's advisory for the definitive affected build ranges since none are enumerated here. Until patched, minimize connection of untrusted USB mass-storage devices and monitor Microsoft advisories, CISA KEV, and vendor communications for signs of in-the-wild exploitation.
| Microsoft Windows USB Mass Storage Class Driver (in-box driver component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-20, CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.