CVE-2026-72953
massLocal Privilege Escalation via Heap Buffer Overflow in Windows USB Driver
CVE-2026-72953 is a heap-based buffer overflow (CWE-122) in the Windows USB Driver, a component bundled with Microsoft's operating system. It can be triggered by an authorized local user who submits malformed data to the USB driver, with no user interaction required. Successful exploitation allows the attacker to escalate from low privileges to elevated rights on the host, with high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). Any Windows system containing the affected driver is potentially exposed; the disclosure data does not specify an affected version range, so defenders should consult Microsoft's advisory for the exact builds. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within the next 30 days (25th percentile).
What to do: Install the Microsoft security update addressing CVE-2026-72953 when it becomes available and check the Microsoft advisory for the exact affected Windows versions, since the disclosure does not list a version range. In the meantime, limit local sign-in rights on multi-user Windows hosts, as exploitation requires an authorized local account. No public PoC or in-the-wild exploitation is known, so standard patch-cadence handling is appropriate rather than emergency patching.
| Microsoft Windows USB Driver | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.