ZeroHour

CVE-2026-69584

mass

Local Privilege Escalation via Integer Overflow in Windows USB Video Driver

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69584 is an integer overflow/wraparound flaw (CWE-190) in the Windows USB Video Driver, the inbox driver that handles USB Video Class devices such as webcams. An authorized attacker with low privileges on a local machine can trigger the overflow through the driver's processing of USB video data, causing memory corruption at the kernel level. Successful exploitation elevates the attacker's privileges to administrator/SYSTEM level, yielding high confidentiality, integrity and availability impact — effectively full local compromise of the host. Because the driver ships as a built-in Windows component, essentially the entire Windows installed base is in scope, though real-world exploitation requires an attacker to already run low-privileged code on the target, typically on a machine with a USB video device attached. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days, so no active exploitation is currently known.

What to do: Apply Microsoft's update for CVE-2026-69584 via Windows Update on all affected systems, prioritizing workstations, VDI/Remote Desktop hosts, and shared or kiosk machines where untrusted users can execute code locally. No public exploits or workarounds are known, so standard patch-cycle timing is reasonable; after patching, confirm the updated USB Video Driver (usbvideo.sys) is in place on high-risk hosts.

Affected
Microsoft Windows USB Video Driver (inbox USB Video Class driver, usbvideo.sys)
Estimated exposure
mass≈1 billion+ Windows devices (driver is an inbox Windows component) — The USB Video Class driver ships with Windows and loads on systems with built-in or attached UVC cameras, so exposure is at the scale of Microsoft's reported >1 billion active Windows devices, with practical risk limited to hosts where…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.