Executive brief
A security vulnerability exists in the Windows USB Print Driver, a component responsible for managing communication between the operating system and USB-connected printers. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A race condition vulnerability (CWE-362) exists in the Windows USB Print Driver due to improper synchronization when accessing shared resources. The flaw also involves an out-of-bounds read (CWE-125) condition. An attacker with low-privileged local access can exploit this by timing specific execution threads to manipulate shared memory, leading to local privilege escalation (LPE). Successful exploitation allows the attacker to gain SYSTEM-level privileges. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server 2025.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory