ZeroHour

CVE-2026-72953

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows USB Driver

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72953 is a heap-based buffer overflow (CWE-122) in the Windows USB Driver, a component bundled with Microsoft's operating system. It can be triggered by an authorized local user who submits malformed data to the USB driver, with no user interaction required. Successful exploitation allows the attacker to escalate from low privileges to elevated rights on the host, with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Any Windows system containing the affected driver is potentially exposed; the disclosure data does not specify an affected version range, so defenders should consult Microsoft's advisory for the exact builds. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days (25th percentile).

What to do: Install the Microsoft security update addressing CVE-2026-72953 when it becomes available and check the Microsoft advisory for the exact affected Windows versions, since the disclosure does not list a version range. In the meantime, limit local sign-in rights on multi-user Windows hosts, as exploitation requires an authorized local account. No public PoC or in-the-wild exploitation is known, so standard patch-cadence handling is appropriate rather than emergency patching.

Affected
Microsoft Windows USB Driver
Estimated exposure
masswell over 1 billion Windows devices (driver component ships with the OS) — The USB driver is a core component bundled with Windows, which runs on more than one billion devices per Microsoft's published figures, so nearly every Windows installation contains the affected component, though only systems with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.