Executive brief
The Windows USB Audio Class driver (usbaudio.sys) contains a memory vulnerability that allows a local user with existing system access to elevate their privileges. An attacker who exploits this flaw could gain administrator-level control of an affected Windows system, potentially leading to complete system compromise, installation of malware, or unauthorized data access.
Technical details
A use-after-free vulnerability exists in the Windows USB Audio Class driver (usbaudio.sys). The vulnerability allows an authenticated local attacker to elevate privileges on the affected system. Exploitation requires the attacker to have local access to the machine. Successful exploitation grants the attacker elevated (administrative) privileges. A security patch from Microsoft is available to remediate this issue.
Affected products
- Microsoft Windows Unknown
Timeline
- 2026-09-08: disclosed