ZeroHour

CVE-2026-69413

mass

Use-after-free local privilege escalation in Windows USB Audio Class driver

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-69413 is a use-after-free (CWE-416) vulnerability in usbaudio.sys, the in-box Windows USB Audio Class kernel driver maintained by Microsoft. Because the attack vector is local (AV:L) with high attack complexity, exploitation requires an attacker who already holds low-privileged authorized access on the host and would involve the driver's handling of USB audio device operations, likely under timing-sensitive conditions. A successful exploit allows the attacker to elevate privileges locally, gaining high-impact control over confidentiality, integrity, and availability of the machine (kernel-level access). Any Windows system using the in-box USB audio driver is in scope, though practical risk concentrates on hosts where untrusted or low-privileged users can attach or interact with USB audio devices. As of this data there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.3% (17th percentile) probability of exploitation within 30 days, indicating low near-term exploitation risk.

What to do: Apply Microsoft's security update addressing CVE-2026-69413 to all Windows endpoints as part of your regular patch cycle, prioritizing multi-user systems, VDI/session hosts, and workstations where low-privileged users can plug in USB peripherals. Since the flaw is local-only, standard hardening (restricting physical/USB device attachment for untrusted users) limits exposure, and no public exploit exists yet, so there is no need for emergency patching outside normal Windows update channels. Track Microsoft's advisory for the definitive affected version ranges and update package.

Affected
Microsoft Windows USB Audio Class driver (usbaudio.sys)
Estimated exposure
mass>1,000,000,000 Windows installations (usbaudio.sys is an in-box OS driver) — usbaudio.sys ships in-box with Windows and is present on effectively every Windows PC, an installed base measured in the hundreds of millions to over a billion, though practical exploitation risk is limited to hosts where local users can…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.