ZeroHour

CVE-2026-69295

mass

Out-of-bounds read in Microsoft Windows USB Driver enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69295 is an out-of-bounds read vulnerability (CWE-125, also mapped to CWE-20) in the Windows USB Driver, classified by Microsoft (the CNA) as an Elevation of Privilege flaw. The available data does not document the exact trigger path, but the flaw class implies the driver reads beyond the bounds of an allocated buffer when handling input, and the CVSS vector indicates a local attack surface requiring only low privileges with no user interaction. An attacker who already has low-privileged access to a machine ('an authorized attacker') can leverage the flaw to gain elevated privileges locally, with the vector rating high impact to confidentiality, integrity, and availability on the compromised host. Any Windows installation that ships the affected USB driver is potentially affected; Microsoft has not provided affected build/version ranges in the data available here. Exploitation status is quiet: no public proof-of-concept, no listing in CISA's KEV, and EPSS estimates only a 0.3% (25th percentile) probability of exploitation in the next 30 days.

What to do: Patch via Windows Update as soon as Microsoft's security update for the USB driver is released, and consult the MSRC advisory for the exact affected editions/builds since no version range is provided in this data. Because exploitation requires prior low-privileged local access, prioritize hosts where untrusted users or untrusted USB devices are common (shared workstations, kiosks, jump hosts, RDS servers) and enforce least privilege. Given the absence of a public PoC and low EPSS, this can be handled in the regular patching cycle rather than as an emergency, but verify the driver update lands on all endpoints.

Affected
Microsoft Windows USB Driver
Estimated exposure
masshundreds of millions of Windows devices (the USB driver is an inbox component of the Windows install base) — Public usage-share data puts the Windows install base above 1.4 billion devices, and a driver component shipped with Windows would be present on effectively all of them, so the order of magnitude is mass even though no per-version counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-20, CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.