CVE-2026-69707
massInteger Overflow in Windows USB Audio Class Driver Allows Local Privilege Escalation
CVE-2026-69707 is an integer overflow or wraparound flaw (CWE-190) in usbaudio.sys, the USB Audio Class driver that ships in-box with Microsoft Windows. An attacker who already holds a low-privileged foothold on a local machine can trigger the flaw through the driver's processing of USB audio data, with no user interaction required per the CVSS vector. Successful exploitation elevates the attacker's privileges to kernel level, granting high impact on confidentiality, integrity, and availability of the host. Any Windows system that loads the in-box USB Audio Class driver is in scope; the provided data does not list affected version ranges, so defenders should consult Microsoft's advisory for specifics. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and the 0.3% EPSS score (25th percentile) indicates a low probability of near-term exploitation.
What to do: Apply Microsoft's security update for CVE-2026-69707 via Windows Update, checking Microsoft's advisory for the affected Windows versions and the patched usbaudio.sys build. Prioritize hosts where untrusted or low-privileged users have local sign-in access, such as shared workstations, kiosks, VDI, and Remote Desktop servers, since exploitation requires a local foothold. As interim risk reduction, restrict local sign-in rights to trusted users on multi-user systems and pay attention to hosts that regularly use USB audio devices such as headsets, docking stations, and conference-room speakers.
| Microsoft Windows USB Audio Class driver (usbaudio.sys), an in-box component of Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.