Junglewise Threat Intelligence

CVE-2026-69457: Microsoft Windows USB Driver out-of-bounds read

CVE-2026-69457 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows USB Driver. Vendors: Microsoft.

Executive brief

Windows includes a USB driver component that processes device data. An authorized local attacker can exploit an out-of-bounds read flaw to access sensitive information from system memory, potentially exposing authentication credentials, encryption keys, or other confidential data. This requires local system access and does not allow remote attacks or system compromise.

Technical details

The vulnerability is an out-of-bounds read in the Windows USB Driver that fails to properly validate memory access boundaries when processing USB device requests. An authenticated local attacker can trigger the flaw to read sensitive data from kernel memory or adjacent buffers. The attack requires local access to the system and does not enable code execution; the impact is limited to information disclosure. Microsoft has released security updates to address this issue via patch CVE-2026-69457.

Affected products

  • Microsoft Windows USB Driver <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats