Executive brief
Windows systems include a USB Audio Class driver (usbaudio.sys) that processes audio data from connected USB devices. An attacker with physical access to a machine can exploit an integer overflow flaw in this driver to gain elevated privileges, potentially allowing them to bypass security controls or take full control of the system.
Technical details
The vulnerability is an integer overflow or wraparound condition in the Windows USB Audio Class driver (usbaudio.sys). The flaw allows an attacker to escalate privileges through a physical attack vector, requiring them to connect a malicious USB device to the target machine. This is a low-barrier attack if the machine is physically accessible, and successful exploitation would grant an attacker system-level privileges. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed