Junglewise Threat Intelligence

CVE-2026-69571: Microsoft Windows USB Audio Class driver heap overflow privilege escalation

CVE-2026-69571 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

The Windows USB Audio Class driver (usbaudio.sys) is a core system component that processes audio data from USB devices. A heap buffer overflow in this driver allows a local user with limited privileges to execute code with elevated system permissions, potentially giving an attacker complete control over the affected computer.

Technical details

This vulnerability is a heap-based buffer overflow in usbaudio.sys, the Windows USB Audio Class driver. The flaw allows an authorized local attacker to overflow a heap buffer, which can be exploited to achieve privilege escalation from a standard user account to system level. The attack requires local access and an authenticated user account on the system. Successful exploitation results in arbitrary code execution with elevated privileges. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats