Executive brief
A security vulnerability exists in the Windows USB Print Driver, which manages how the computer communicates with printers connected via USB. An attacker with physical access to a device could exploit this flaw to gain higher-level system permissions, potentially allowing them to bypass security controls or access restricted data. This requires the attacker to have a low-privileged account on the machine and perform specific actions while physically connected to the device.
Technical details
A race condition (CWE-362) and potential use-after-free (CWE-416) vulnerability exist in the Windows USB Print Driver due to improper synchronization of shared resources. The attack vector is physical (AV:P), requiring the attacker to have local user credentials (PR:L) and physical access to the target machine to manipulate USB communication. Successful exploitation allows an attacker to elevate privileges to a higher level, such as SYSTEM. Microsoft has released security updates for affected versions of Windows 11 and Windows Server 2025 to address this issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26100.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD