Junglewise Threat Intelligence

CVE-2026-69490: Microsoft Windows USB Mass Storage Class Driver out-of-bounds read

CVE-2026-69490 · Severity: medium · CVSS 6.8 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows' USB Mass Storage Class Driver is a system component that handles communication with external storage devices like USB drives and portable hard drives. An attacker with physical access to a computer can exploit an out-of-bounds read vulnerability to execute privileged code and take full control of the system, bypassing normal security controls.

Technical details

The vulnerability is an out-of-bounds read in the Windows USB Mass Storage Class Driver that can be exploited through a specially crafted physical USB device. An attacker must have local physical access to the target machine to connect the malicious USB device. Successful exploitation allows privilege escalation to SYSTEM level, enabling complete system compromise. The attack does not require prior authentication or user interaction beyond connecting the device. Microsoft has issued security updates to remediate this vulnerability.

Affected products

  • Microsoft Windows USB Mass Storage Class Driver Multiple Windows versions

Timeline

  • 2026-09-08: disclosed

References