Executive brief
The Windows USB Audio Class driver (usbaudio.sys) contains a memory access flaw that allows a local attacker with system access to read sensitive data from system memory. While exploiting this requires existing system permissions, a successful attack could leak sensitive information used by the operating system or other applications, potentially compromising data confidentiality.
Technical details
The vulnerability is an out-of-bounds read in the Windows USB Audio Class driver (usbaudio.sys). The flaw allows an authorized local attacker to read memory beyond the intended bounds of a buffer, disclosing sensitive kernel or driver memory. The attack requires local access to the system and likely elevated privileges or user-mode interaction with the vulnerable USB audio driver. An attacker exploiting this vulnerability can leak confidential information resident in adjacent memory regions. Microsoft has released patches addressing this issue via their security update channels.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed