CVE-2026-69413
massUse-after-free local privilege escalation in Windows USB Audio Class driver
CVE-2026-69413 is a use-after-free (CWE-416) vulnerability in usbaudio.sys, the in-box Windows USB Audio Class kernel driver maintained by Microsoft. Because the attack vector is local (AV:L) with high attack complexity, exploitation requires an attacker who already holds low-privileged authorized access on the host and would involve the driver's handling of USB audio device operations, likely under timing-sensitive conditions. A successful exploit allows the attacker to elevate privileges locally, gaining high-impact control over confidentiality, integrity, and availability of the machine (kernel-level access). Any Windows system using the in-box USB audio driver is in scope, though practical risk concentrates on hosts where untrusted or low-privileged users can attach or interact with USB audio devices. As of this data there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.3% (17th percentile) probability of exploitation within 30 days, indicating low near-term exploitation risk.
What to do: Apply Microsoft's security update addressing CVE-2026-69413 to all Windows endpoints as part of your regular patch cycle, prioritizing multi-user systems, VDI/session hosts, and workstations where low-privileged users can plug in USB peripherals. Since the flaw is local-only, standard hardening (restricting physical/USB device attachment for untrusted users) limits exposure, and no public exploit exists yet, so there is no need for emergency patching outside normal Windows update channels. Track Microsoft's advisory for the definitive affected version ranges and update package.
| Microsoft Windows USB Audio Class driver (usbaudio.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.