CVE-2026-72962
massLocal Privilege Escalation via Heap Buffer Overflow in Windows USB Video Driver
CVE-2026-72962 is a heap-based buffer overflow (CWE-122) in the Windows USB Video Driver, the Microsoft component that handles USB video-class devices such as webcams. Per the CVSS vector, an authorized local attacker can trigger the overflow without user interaction (AV:L/AC:L/UI:N), with the attack scenario requiring high existing privileges (PR:H). Successful exploitation lets the attacker elevate privileges, and the Scope:Changed metric with high C/I/A impact indicates the compromise crosses a security boundary beyond the attacker's original context, consistent with kernel-level access. All Windows installations that include the affected driver are potentially exposed; the source data does not enumerate specific Windows versions, so defenders should consult Microsoft's advisory for the affected version list. Exploitation status is currently quiet: there is no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at just 0.3% (25th percentile), though the 8.2 High severity warrants prompt patching.
What to do: Apply Microsoft's security update for CVE-2026-72962 as soon as it is available and verify the affected Windows version list in Microsoft's advisory, since this data does not include specific build numbers. In the interim, restrict local sign-in rights on sensitive hosts and inventory systems where untrusted users can connect USB video devices (webcams, capture devices). Because no public PoC or in-the-wild exploitation is known, treat this as a routine-patch item rather than an emergency, but close it in your normal update cycle given the High severity.
| Microsoft Windows USB Video Driver (Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.