Executive brief
Windows USB Driver contains an out-of-bounds read vulnerability that could allow an authorized user on the system to elevate their privileges. An attacker with local access could exploit this flaw to gain administrative control of the system, potentially leading to complete system compromise and unauthorized access to sensitive data.
Technical details
An out-of-bounds read vulnerability exists in the Windows USB Driver that can be exploited to perform local privilege escalation. The vulnerability is triggered through improper memory bounds checking when processing USB-related operations, allowing an authenticated attacker with local system access to read memory beyond intended boundaries. Exploitation requires local access and prior authorization on the system. A successful exploit allows an attacker to escalate their privileges to a higher level, potentially gaining administrative access. Microsoft has released security patches to address this vulnerability.
Affected products
- Microsoft Windows USB Driver
Timeline
- 2026-09-08: disclosed