ZeroHour

CVE-2026-69503

mass

Stack Buffer Overflow in Windows USB Driver Allows Network Privilege Escalation

CVSS 3.1
8.0 high
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-69503 is a stack-based buffer overflow (CWE-121) in the Microsoft Windows USB Driver. According to the CVSS vector, an attacker who already holds limited privileges on the target can trigger the flaw over a network, with user interaction required as part of the attack path. Successful exploitation allows the attacker to elevate privileges on the affected system, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.0, High). All Windows installations that include the affected USB driver component are potentially exposed, though the available data does not specify which Windows version ranges are affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a 0.8% probability of exploitation within 30 days (percentile 53), indicating no known in-the-wild exploitation at this time.

What to do: Apply the patched Windows USB driver as soon as Microsoft publishes it, via Windows Update or the Microsoft advisory, and confirm your Windows versions against Microsoft's affected-products list. In the meantime, prioritize patching and restricting low-privilege remote access (e.g., RDS/VDI and multi-user hosts), since exploitation requires an already-authorized attacker and user interaction. Monitor for a public PoC or KEV addition given the moderate EPSS score of 0.8%.

Affected
Microsoft Windows USB Driver
Estimated exposure
masson the order of hundreds of millions of Windows systems (USB driver ships in-box with Windows across a multi-hundred-million to billion-plus device installed… — The USB driver is an in-box Windows component, so exposure plausibly spans the commonly cited ~1 billion+ device Windows installed base, tempered by the unknown set of affected Windows versions and by the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.