Junglewise Threat Intelligence

CVE-2026-69413: Microsoft Windows USB Audio Class driver use-after-free privilege escalation

CVE-2026-69413 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

The Windows USB Audio Class driver (usbaudio.sys) contains a memory vulnerability that allows a local user with existing system access to elevate their privileges. An attacker who exploits this flaw could gain administrator-level control of an affected Windows system, potentially leading to complete system compromise, installation of malware, or unauthorized data access.

Technical details

A use-after-free vulnerability exists in the Windows USB Audio Class driver (usbaudio.sys). The vulnerability allows an authenticated local attacker to elevate privileges on the affected system. Exploitation requires the attacker to have local access to the machine. Successful exploitation grants the attacker elevated (administrative) privileges. A security patch from Microsoft is available to remediate this issue.

Affected products

  • Microsoft Windows Unknown

Timeline

  • 2026-09-08: disclosed

References

Related threats