Junglewise Threat Intelligence

CVE-2026-69527: Microsoft Windows USB Mass Storage Class Driver out-of-bounds read

CVE-2026-69527 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows systems include a USB Mass Storage Class Driver component that processes external storage device connections. An authorized local attacker can exploit an out-of-bounds read vulnerability in this driver to access sensitive information from system memory, potentially exposing confidential data or enabling further attacks.

Technical details

The vulnerability is an out-of-bounds read flaw in the Windows USB Mass Storage Class Driver, a kernel-mode component responsible for managing USB storage devices. The defect allows an authenticated local attacker to read memory outside intended buffer boundaries. The attack requires local system access (authenticated user context) but does not require special kernel privileges. Successful exploitation can disclose sensitive information from kernel memory or other processes. Microsoft has released security updates to address this vulnerability; patching is recommended.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats