CVE-2026-69295
massOut-of-bounds read in Microsoft Windows USB Driver enables local privilege escalation
CVE-2026-69295 is an out-of-bounds read vulnerability (CWE-125, also mapped to CWE-20) in the Windows USB Driver, classified by Microsoft (the CNA) as an Elevation of Privilege flaw. The available data does not document the exact trigger path, but the flaw class implies the driver reads beyond the bounds of an allocated buffer when handling input, and the CVSS vector indicates a local attack surface requiring only low privileges with no user interaction. An attacker who already has low-privileged access to a machine ('an authorized attacker') can leverage the flaw to gain elevated privileges locally, with the vector rating high impact to confidentiality, integrity, and availability on the compromised host. Any Windows installation that ships the affected USB driver is potentially affected; Microsoft has not provided affected build/version ranges in the data available here. Exploitation status is quiet: no public proof-of-concept, no listing in CISA's KEV, and EPSS estimates only a 0.3% (25th percentile) probability of exploitation in the next 30 days.
What to do: Patch via Windows Update as soon as Microsoft's security update for the USB driver is released, and consult the MSRC advisory for the exact affected editions/builds since no version range is provided in this data. Because exploitation requires prior low-privileged local access, prioritize hosts where untrusted users or untrusted USB devices are common (shared workstations, kiosks, jump hosts, RDS servers) and enforce least privilege. Given the absence of a public PoC and low EPSS, this can be handled in the regular patching cycle rather than as an emergency, but verify the driver update lands on all endpoints.
| Microsoft Windows USB Driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-20, CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.