CVE-2026-69423
massHeap Buffer Overflow in Microsoft Windows USB Video Driver Allows Elevation of Privilege
CVE-2026-69423 is a heap-based buffer overflow (CWE-122) in the Windows USB Video Driver, the Windows component that processes USB video devices. Per Microsoft's description, an authorized (authenticated, low-privileged) attacker can exploit it over a network, and the CVSS vector (AV:N/AC:L/PR:L/UI:R) further indicates that some form of user interaction is required to trigger the overflow. Successful exploitation elevates the attacker's privileges on the affected host, with the CVSS impact metrics rating confidentiality, integrity, and availability impact as high. Any Windows system where the affected USB Video Driver component is present and exercised is exposed, although the available data does not enumerate specific affected Windows versions. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7 percent probability of exploitation within 30 days.
What to do: Install Microsoft's security update addressing CVE-2026-69423 on your next Windows patch cycle, checking the MSRC advisory for the KBs and versions applicable to each Windows release in your estate. Prioritize hosts where low-privileged users work with USB cameras or webcams and shared or remotely accessed systems such as RDP/VDI, and as an interim measure restrict connections of untrusted USB video devices. With no public exploit and low EPSS, standard patch-cadence handling is reasonable, but confirm remediation across all endpoints.
| Microsoft Windows (USB Video Driver component) | Affected Windows releases not enumerated in the available data; see Microsoft's official advisory (Microsoft is the assigned CNA) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.