CVE-2026-69422
massLocal privilege elevation via use-after-free in Windows USB Video Driver
CVE-2026-69422 is a use-after-free (CWE-416) in the Windows USB Video Driver, the in-box Microsoft driver that handles USB Video Class devices such as webcams and capture cameras. An authorized attacker who already has low-privileged code execution on a local machine can trigger the flawed memory handling in the driver (per CVSS: local vector, high attack complexity, low privileges, no user interaction required). Successful exploitation elevates the attacker's privileges on the host, with high impact on confidentiality, integrity, and availability. Any Windows system running the affected driver is exposed, with risk concentrated on machines where USB video devices (including internal laptop webcams, which commonly present as UVC devices) are attached. As of this analysis there is no known exploitation, no public proof-of-concecept, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Install the Microsoft update addressing CVE-2026-69422 for your Windows release via Windows Update/WSUS during the regular monthly patch cycle, prioritizing shared or kiosk-style systems where untrusted low-privileged users have local access and USB cameras are attached. Confirm post-patch that the USB Video Driver binary has been updated on high-value hosts. Given the absence of in-the-wild exploitation, public PoCs, and KEV listing, this can be handled in the standard cadence rather than emergency patching.
| Microsoft Windows USB Video Driver (USB Video Class driver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.