ZeroHour

CVE-2026-68840

mass

Local Privilege Escalation Race Condition in Windows USB Driver

CVSS 3.1
7.0 high
EPSS
<1%p5
Published
()
Modified
AI analysis

CVE-2026-68840 is a race condition (improper synchronization of concurrent execution on a shared resource, tracked as CWE-362 with a related use-after-free pattern CWE-416) in the Windows USB Driver. A local, already-authorized low-privileged attacker can trigger the flaw by running code that races the driver's handling of shared resources, and the high attack complexity (AC:H) means timing must land just right. Successful exploitation yields elevation of privilege on the local machine, with high impact on confidentiality, integrity, and availability from that vantage point. Any Windows system with the affected USB driver stack is in scope, though the data does not specify which Windows versions or editions. There is currently no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 0.2% (5th percentile), indicating no known exploitation to date.

What to do: Check Microsoft's advisory for the exact affected Windows versions and apply the corresponding Windows security update as part of your regular patch cycle; no public PoC or in-the-wild exploitation is known, and the high attack complexity lowers near-term urgency. Prioritize multi-user hosts, shared workstations, and kiosk-style systems where untrusted local accounts exist, since those give attackers the required low-privileged foothold. There is no practical workaround beyond patching, so monitor vendor channels for updated build information.

Affected
Microsoft Windows USB Driver
Estimated exposure
masshundreds of millions of Windows endpoints (the USB driver stack ships with Windows) — The Windows USB driver component is part of the standard Windows driver stack, so the affected install base is on the order of the global Windows desktop/laptop footprint, though the specific builds affected are not stated in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.