CVE-2026-69571
massHeap overflow in Windows USB Audio Class driver enables local privilege escalation
CVE-2026-69571 is a heap-based buffer overflow (CWE-122) in usbaudio.sys, the USB Audio Class driver shipped inbox with Windows. The flaw is exploited locally through the USB Audio Class driver — most plausibly while it processes input from a connected USB audio device, although Microsoft's description does not specify the exact trigger. An authorized attacker who already holds a low-privileged account on the machine can leverage it to elevate privileges, with high confidentiality, integrity, and availability impact per the CVSS vector (7.8, AV:L/AC:L/PR:L/UI:N). Any Windows system carrying the inbox usbaudio.sys driver is potentially affected, but the available data does not enumerate specific affected Windows versions or builds. Exploitation status: no public proof-of-concept exists, the CVE is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile), so no in-the-wild exploitation is currently known.
What to do: Apply Microsoft's security update for CVE-2026-69571 via Windows Update when released, prioritizing multi-user and shared systems (RDS hosts, VDI, kiosks) and endpoints where unprivileged users can connect USB audio devices; consult Microsoft's advisory for exact affected and fixed builds, since version ranges are not specified in the data at hand. Until patching, restricting local logon rights and limiting physical USB access on sensitive hosts reduces practical risk. Given EPSS of 0.3%, no KEV listing, and no public PoC, a standard patch cadence is defensible for low-risk single-user endpoints.
| Microsoft Windows USB Audio Class driver (usbaudio.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.