CVE-2026-69687
massLocal Privilege Escalation via Integer Underflow in Windows USB Audio Class Driver (usbaudio.sys)
CVE-2026-69687 is an integer underflow (wraparound, CWE-191) in usbaudio.sys, the inbox Windows kernel driver for USB Audio Class devices. An authorized attacker who already has low-privileged local code execution can trigger the faulty length/size handling to corrupt kernel memory and elevate privileges. Successful exploitation grants high-privilege (kernel/SYSTEM-level) access, giving the attacker full control of the host including the ability to bypass user-mode security boundaries. Any Windows installation shipping the affected driver is in scope, though Microsoft's published data does not enumerate specific Windows version ranges. Exploitation status: no public proof-of-concept, not listed in CISA's KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.
What to do: Apply the Windows security update for CVE-2026-69687 from Microsoft when it is available, and prioritize hosts that allow untrusted or low-privilege local logons or unattended physical USB access. Until patching, limit local untrusted code execution and physical access to USB ports, and verify remediation by confirming the patched usbaudio.sys driver version installed by the update.
| Microsoft Windows USB Audio Class driver (usbaudio.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-191
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.