Executive brief
A security vulnerability exists in the Windows USB Print Driver, which manages communication between the operating system and USB-connected printers. An authorized user with low-level access to a system could exploit a timing error to gain higher-level administrative privileges. This could allow an attacker to take full control of the affected computer, potentially leading to unauthorized data access or system-wide changes.
Technical details
A race condition (CWE-362) exists in the Windows USB Print Driver due to improper synchronization when accessing shared resources. An attacker with local access and low privileges (PR:L) can exploit this flaw by timing specific executions to trigger the synchronization error. Successful exploitation allows the attacker to elevate privileges to a higher level, potentially gaining SYSTEM-level access. The vulnerability also involves an out-of-bounds read (CWE-125) component. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server 2025.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory