Executive brief
Microsoft Windows includes a USB Audio Class driver (usbaudio.sys) that handles audio devices connected via USB. A heap buffer overflow vulnerability in this driver could allow an authorized local attacker to elevate their privileges and gain administrative control over the system, potentially compromising all data and operations on the affected computer.
Technical details
A heap-based buffer overflow exists in the Windows USB Audio Class driver (usbaudio.sys) that can be triggered by an authorized local attacker. The vulnerability is reachable via local attack vector and requires the attacker to already have user-level privileges on the system. Successful exploitation allows privilege escalation from user to system/administrative level. The vulnerability is not currently known to be exploited in the wild. A patch is available from Microsoft.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed