ZeroHour

CVE-2026-69571

mass

Heap overflow in Windows USB Audio Class driver enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69571 is a heap-based buffer overflow (CWE-122) in usbaudio.sys, the USB Audio Class driver shipped inbox with Windows. The flaw is exploited locally through the USB Audio Class driver — most plausibly while it processes input from a connected USB audio device, although Microsoft's description does not specify the exact trigger. An authorized attacker who already holds a low-privileged account on the machine can leverage it to elevate privileges, with high confidentiality, integrity, and availability impact per the CVSS vector (7.8, AV:L/AC:L/PR:L/UI:N). Any Windows system carrying the inbox usbaudio.sys driver is potentially affected, but the available data does not enumerate specific affected Windows versions or builds. Exploitation status: no public proof-of-concept exists, the CVE is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile), so no in-the-wild exploitation is currently known.

What to do: Apply Microsoft's security update for CVE-2026-69571 via Windows Update when released, prioritizing multi-user and shared systems (RDS hosts, VDI, kiosks) and endpoints where unprivileged users can connect USB audio devices; consult Microsoft's advisory for exact affected and fixed builds, since version ranges are not specified in the data at hand. Until patching, restricting local logon rights and limiting physical USB access on sensitive hosts reduces practical risk. Given EPSS of 0.3%, no KEV listing, and no public PoC, a standard patch cadence is defensible for low-risk single-user endpoints.

Affected
Microsoft Windows USB Audio Class driver (usbaudio.sys)
Estimated exposure
mass~1.4 billion Windows endpoints (inbox driver present on effectively all Windows installs) — usbaudio.sys ships by default with Windows, so potential exposure approaches Microsoft's ~1.4 billion active Windows devices, though actual exploitability requires a local low-privileged account and conditions Microsoft has not detailed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.