ZeroHour

CVE-2026-69423

mass

Heap Buffer Overflow in Microsoft Windows USB Video Driver Allows Elevation of Privilege

CVSS 3.1
8.0 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-69423 is a heap-based buffer overflow (CWE-122) in the Windows USB Video Driver, the Windows component that processes USB video devices. Per Microsoft's description, an authorized (authenticated, low-privileged) attacker can exploit it over a network, and the CVSS vector (AV:N/AC:L/PR:L/UI:R) further indicates that some form of user interaction is required to trigger the overflow. Successful exploitation elevates the attacker's privileges on the affected host, with the CVSS impact metrics rating confidentiality, integrity, and availability impact as high. Any Windows system where the affected USB Video Driver component is present and exercised is exposed, although the available data does not enumerate specific affected Windows versions. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7 percent probability of exploitation within 30 days.

What to do: Install Microsoft's security update addressing CVE-2026-69423 on your next Windows patch cycle, checking the MSRC advisory for the KBs and versions applicable to each Windows release in your estate. Prioritize hosts where low-privileged users work with USB cameras or webcams and shared or remotely accessed systems such as RDP/VDI, and as an interim measure restrict connections of untrusted USB video devices. With no public exploit and low EPSS, standard patch-cadence handling is reasonable, but confirm remediation across all endpoints.

Affected
Microsoft Windows (USB Video Driver component)Affected Windows releases not enumerated in the available data; see Microsoft's official advisory (Microsoft is the assigned CNA)
Estimated exposure
mass~1 billion Windows installations (inbox OS driver component; global Windows installed base is ~1.4 billion devices) — The USB Video Driver ships in-box with Windows, so the vulnerable component is plausibly present across most of the roughly 1.4-billion-device Windows installed base, though practical exploitability is narrower because it requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.