Junglewise Threat Intelligence

CVE-2026-69422: Microsoft Windows USB Video Driver use-after-free privilege escalation

CVE-2026-69422 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows USB Video Driver, a system component that handles USB video device communication, contains a use-after-free vulnerability that allows an authenticated local attacker to execute arbitrary code with elevated system privileges. This could enable an attacker to gain full control of an affected system, compromising all data and operations on that device.

Technical details

A use-after-free vulnerability exists in the Windows USB Video Driver, where memory is accessed after being freed, leading to potential code execution. The vulnerability requires an authenticated attacker with local system access to trigger. An attacker can exploit this flaw to escalate privileges from a standard user context to system/kernel level, allowing arbitrary code execution with the highest privileges on the system. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats