CVE-2026-69270
massHeap Buffer Overflow in Windows USB Audio Class Driver Enables Local Privilege Escalation
CVE-2026-69270 is a heap-based buffer overflow (CWE-122, arising from improper input validation, CWE-20) in usbaudio.sys, the in-box Windows kernel driver for USB Audio Class devices. A local, low-privileged ('authorized') attacker can trigger the overflow, most plausibly by causing the driver to process malformed data associated with a USB audio device, corrupting kernel heap memory. Successful exploitation yields kernel-mode code execution, allowing the attacker to elevate from a low-privilege account to SYSTEM and gain high impact on confidentiality, integrity, and availability of the host. Exposure is broad because the driver ships in the box with Windows, though the affected Windows version ranges are not specified in the available data and defenders should consult Microsoft's advisory for specifics. There is no known public proof of concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so it is not known to be exploited.
What to do: Apply Microsoft's security update for CVE-2026-69270 through your normal patch cycle; with no public PoC, no KEV listing, and very low EPSS, emergency patching is not warranted. Prioritize shared endpoints, kiosks, VDI/RDS hosts, and any machines where untrusted or low-privileged users can connect USB audio devices, and consider device-installation policy (e.g., restricting USB audio class devices) as an interim control. Check Microsoft's advisory for the precise affected Windows versions and patched build numbers before rollout.
| Microsoft Windows USB Audio Class driver (usbaudio.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-20, CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.