ZeroHour

CVE-2026-69859

mass

Microsoft Windows USB Audio Class Driver TOCTOU Race Allows Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-69859 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367, with CWE-191 also cited) in usbaudio.sys, the in-box Windows USB Audio Class driver, assigned by Microsoft. An attacker who already has low-privileged access on the local machine must win a timing race between the driver's validation of a USB audio request and its subsequent use of that resource, which the high attack-complexity score (AC:H) reflects; no user interaction or network access is required. Successful exploitation elevates the attacker's privileges on the local system, with high impact to confidentiality, integrity, and availability. Any Windows system carrying the in-box USB Audio Class driver is potentially affected, though the source data does not enumerate specific Windows version ranges. As of this analysis there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.2% probability of exploitation within 30 days (9th percentile).

What to do: Monitor Microsoft's advisory for this CVE and apply the usbaudio.sys driver update as soon as Microsoft publishes the affected version ranges and fixes. Prioritize multi-user and shared systems (RDS/VDI hosts, kiosks, shared workstations) where untrusted local users can log on and attach USB audio devices; as interim mitigation, restrict local logon rights or limit USB device installation via device-installation policy.

Affected
Microsoft Windows USB Audio Class driver (usbaudio.sys)
Estimated exposure
mass≈1 billion Windows installations (in-box driver present on virtually all Windows systems) — usbaudio.sys ships in-box with Windows, so the candidate population is effectively the entire Windows installed base (on the order of a billion devices); the practical attack surface is limited to systems where low-privileged local users…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-191, CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.