Executive brief
A security vulnerability exists in the Windows USB Audio driver, which manages how the computer interacts with external audio devices like headsets and speakers. An attacker with physical access to a computer could exploit this flaw by plugging in a malicious USB device to access sensitive information stored in the system's memory. This could lead to the theft of data or help an attacker bypass other security protections on the device.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Windows USB Audio Class driver (usbaudio.sys). The flaw is triggered when the driver improperly handles memory boundaries while processing requests from a USB audio device. An attacker with physical access to the target system can exploit this by connecting a specially crafted USB device. Successful exploitation allows the attacker to read sensitive information from kernel memory, which could potentially lead to further system compromise or the disclosure of protected data. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory