CVE-2026-69859
massMicrosoft Windows USB Audio Class Driver TOCTOU Race Allows Local Privilege Escalation
CVE-2026-69859 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367, with CWE-191 also cited) in usbaudio.sys, the in-box Windows USB Audio Class driver, assigned by Microsoft. An attacker who already has low-privileged access on the local machine must win a timing race between the driver's validation of a USB audio request and its subsequent use of that resource, which the high attack-complexity score (AC:H) reflects; no user interaction or network access is required. Successful exploitation elevates the attacker's privileges on the local system, with high impact to confidentiality, integrity, and availability. Any Windows system carrying the in-box USB Audio Class driver is potentially affected, though the source data does not enumerate specific Windows version ranges. As of this analysis there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.2% probability of exploitation within 30 days (9th percentile).
What to do: Monitor Microsoft's advisory for this CVE and apply the usbaudio.sys driver update as soon as Microsoft publishes the affected version ranges and fixes. Prioritize multi-user and shared systems (RDS/VDI hosts, kiosks, shared workstations) where untrusted local users can log on and attach USB audio devices; as interim mitigation, restrict local logon rights or limit USB device installation via device-installation policy.
| Microsoft Windows USB Audio Class driver (usbaudio.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-191, CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.