CVE-2026-69307
massHeap-based overflow in Windows USB Audio Class driver allows local privilege escalation
CVE-2026-69307 is a heap-based buffer overflow (CWE-122) in usbaudio.sys, Microsoft's inbox kernel driver for USB Audio Class devices. A local attacker who is already authenticated with low privileges can trigger the flaw through the Windows USB audio stack, most plausibly by connecting or interacting with a USB audio device whose data overflows a heap buffer, and no user interaction is required beyond that (AV:L/AC:L/PR:L/UI:N). Successful exploitation lets the attacker elevate privileges on the local machine, with high confidentiality, integrity, and availability impact consistent with kernel-level/SYSTEM access. Any Windows system running the affected usbaudio.sys driver is exposed, though the provided data does not enumerate specific Windows versions or builds. Exploitation is not currently observed: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days (25th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69307 as soon as it is offered via Windows Update, prioritizing shared workstations, kiosks, VDI hosts, and endpoints where untrusted or standard-user accounts can plug in USB audio peripherals. Until patched, consider restricting standard users' ability to install or use USB devices (e.g., device-installation restrictions via Group Policy/Intune). Because the provided data omits affected version ranges, verify applicability against Microsoft's official advisory.
| Microsoft Windows USB Audio Class driver (usbaudio.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.