ZeroHour

CVE-2026-69687

mass

Local Privilege Escalation via Integer Underflow in Windows USB Audio Class Driver (usbaudio.sys)

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69687 is an integer underflow (wraparound, CWE-191) in usbaudio.sys, the inbox Windows kernel driver for USB Audio Class devices. An authorized attacker who already has low-privileged local code execution can trigger the faulty length/size handling to corrupt kernel memory and elevate privileges. Successful exploitation grants high-privilege (kernel/SYSTEM-level) access, giving the attacker full control of the host including the ability to bypass user-mode security boundaries. Any Windows installation shipping the affected driver is in scope, though Microsoft's published data does not enumerate specific Windows version ranges. Exploitation status: no public proof-of-concept, not listed in CISA's KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.

What to do: Apply the Windows security update for CVE-2026-69687 from Microsoft when it is available, and prioritize hosts that allow untrusted or low-privilege local logons or unattended physical USB access. Until patching, limit local untrusted code execution and physical access to USB ports, and verify remediation by confirming the patched usbaudio.sys driver version installed by the update.

Affected
Microsoft Windows USB Audio Class driver (usbaudio.sys)
Estimated exposure
mass≈1 billion Windows devices ship the inbox usbaudio.sys driver (practical exposure: hosts with untrusted local users or physical USB access) — usbaudio.sys is a standard inbox component present on essentially all Windows installations, and Windows runs on roughly 1.4 billion active devices per Microsoft's public figures, making the affected-driver population effectively the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-191
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.