ZeroHour

CVE-2026-72962

mass

Local Privilege Escalation via Heap Buffer Overflow in Windows USB Video Driver

CVSS 3.1
8.2 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-72962 is a heap-based buffer overflow (CWE-122) in the Windows USB Video Driver, the Microsoft component that handles USB video-class devices such as webcams. Per the CVSS vector, an authorized local attacker can trigger the overflow without user interaction (AV:L/AC:L/UI:N), with the attack scenario requiring high existing privileges (PR:H). Successful exploitation lets the attacker elevate privileges, and the Scope:Changed metric with high C/I/A impact indicates the compromise crosses a security boundary beyond the attacker's original context, consistent with kernel-level access. All Windows installations that include the affected driver are potentially exposed; the source data does not enumerate specific Windows versions, so defenders should consult Microsoft's advisory for the affected version list. Exploitation status is currently quiet: there is no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at just 0.3% (25th percentile), though the 8.2 High severity warrants prompt patching.

What to do: Apply Microsoft's security update for CVE-2026-72962 as soon as it is available and verify the affected Windows version list in Microsoft's advisory, since this data does not include specific build numbers. In the interim, restrict local sign-in rights on sensitive hosts and inventory systems where untrusted users can connect USB video devices (webcams, capture devices). Because no public PoC or in-the-wild exploitation is known, treat this as a routine-patch item rather than an emergency, but close it in your normal update cycle given the High severity.

Affected
Microsoft Windows USB Video Driver (Windows)
Estimated exposure
mass≈1 billion Windows endpoints carry the in-box USB Video Driver; practical exploit exposure is limited to hosts where local users can attach USB video devices — Windows' installed base exceeds one billion devices and the USB Video Class driver ships in-box with the OS, so the vulnerable code is present on essentially the entire Windows fleet, though exploitation requires local access rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.