CVE-2026-68840
massLocal Privilege Escalation Race Condition in Windows USB Driver
CVE-2026-68840 is a race condition (improper synchronization of concurrent execution on a shared resource, tracked as CWE-362 with a related use-after-free pattern CWE-416) in the Windows USB Driver. A local, already-authorized low-privileged attacker can trigger the flaw by running code that races the driver's handling of shared resources, and the high attack complexity (AC:H) means timing must land just right. Successful exploitation yields elevation of privilege on the local machine, with high impact on confidentiality, integrity, and availability from that vantage point. Any Windows system with the affected USB driver stack is in scope, though the data does not specify which Windows versions or editions. There is currently no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 0.2% (5th percentile), indicating no known exploitation to date.
What to do: Check Microsoft's advisory for the exact affected Windows versions and apply the corresponding Windows security update as part of your regular patch cycle; no public PoC or in-the-wild exploitation is known, and the high attack complexity lowers near-term urgency. Prioritize multi-user hosts, shared workstations, and kiosk-style systems where untrusted local accounts exist, since those give attackers the required low-privileged foothold. There is no practical workaround beyond patching, so monitor vendor channels for updated build information.
| Microsoft Windows USB Driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.