ZeroHour

CVE-2026-68839

mass

Heap-Based Buffer Overflow RCE in Windows USB Mass Storage Class Driver

CVSS 3.1
9.8 critical
EPSS
<1%p54
Published
()
Modified
AI analysis

CVE-2026-68839 is a heap-based buffer overflow (CWE-122, following CWE-20 improper input validation) in the Microsoft Windows USB Mass Storage Class Driver, an in-box component that handles USB mass-storage devices. Microsoft, the assigning CNA, rates it 9.8 CRITICAL with a network attack vector (AV:N/AC:L/PR:N/UI:N), stating that an unauthorized attacker can execute code over a network without privileges or user interaction; the precise trigger sequence and affected build ranges are not detailed in the available data. Successful exploitation yields high impact to confidentiality, integrity, and availability, i.e., arbitrary code execution and potential full compromise of the affected host. Any Windows system carrying this driver is in scope, which effectively means broadly deployed Windows desktop and server installations, pending Microsoft's enumerated version ranges. Exploitation is not currently known: the flaw is not in CISA KEV, no public proof-of-concept is available, and EPSS assigns only a ~0.8% probability of exploitation within 30 days (54th percentile).

What to do: Apply Microsoft's security update for CVE-2026-68839 across all supported Windows releases as soon as it is available, and check Microsoft's advisory for the definitive affected build ranges since none are enumerated here. Until patched, minimize connection of untrusted USB mass-storage devices and monitor Microsoft advisories, CISA KEV, and vendor communications for signs of in-the-wild exploitation.

Affected
Microsoft Windows USB Mass Storage Class Driver (in-box driver component)
Estimated exposure
mass≈1 billion+ Windows installations (driver ships in-box with the OS) — The USB Mass Storage Class Driver is an in-box Windows component present on effectively every Windows desktop/server installation, and the worldwide Windows install base is on the order of a billion-plus devices; actual exploitability per…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

Weakness
CWE-20, CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.