Executive brief
A security vulnerability exists in the Windows USB Hub Driver, which manages how the computer communicates with USB devices. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
This vulnerability is classified as an untrusted pointer dereference (CWE-822) within the Windows USB Hub Driver. An attacker with local access and low-level user privileges can exploit this flaw to execute code with elevated system privileges. The attack vector is local, requiring the attacker to already have a foothold on the target machine, but it does not require user interaction. Microsoft has released security updates to address this issue across affected versions of Windows 10 and Windows Server.
Affected products
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates released by Microsoft