ZeroHour

CVE-2026-69319

mass

Race Condition in Windows USB Video Driver Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-69319 is a race condition involving improper synchronization of a shared resource (CWE-362, with an associated use-after-free risk per CWE-416) in the Windows USB Video Driver. It is triggered when concurrent operations race on a shared driver resource, and can be exploited by an authorized local attacker who is already able to run low-privileged code on the target machine. Successful exploitation elevates the attacker's privileges locally, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.0, AV:L/AC:H/PR:L/UI:N). Any Windows system running the affected USB Video Driver component is exposed in principle, though high attack complexity and the local-access requirement reduce practical risk. No exploitation is known: there is no public proof-of-concept, it is not listed in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days (9th percentile).

What to do: Apply Microsoft's security update for the Windows USB Video Driver via Windows Update as soon as the fix ships, since no fixed version or KB number is provided in the source data. Prioritize multi-user hosts such as RDS/session servers, kiosks, and shared workstations where low-privileged local code execution is more likely, and verify the updated driver after patching. Given the high attack complexity, local-only vector, and absence of known exploitation, routine patch-cycle prioritization is reasonable; no workarounds or public exploit exist.

Affected
Microsoft Windows USB Video Driver
Estimated exposure
mass≈1B Windows installations (inbox driver, present on broadly all modern Windows systems with USB video/webcam devices) — The USB Video Class driver ships inbox with Windows, so the theoretical exposed population is bounded by the Windows installed base (~1B+ devices), reduced in practice to systems where a local user can execute code and the driver services…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.