Junglewise Threat Intelligence

CVE-2026-69584: Microsoft Windows USB Video Driver integer overflow

CVE-2026-69584 · Severity: high · CVSS 7.8 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

Windows includes a USB Video Class driver for handling video devices connected via USB. An authorized local attacker can exploit an integer overflow in this driver to gain elevated system privileges, potentially allowing unauthorized access to sensitive system resources or complete system compromise.

Technical details

The vulnerability is an integer overflow or wraparound flaw in the Windows USB Video Driver. An authenticated/authorized local attacker can trigger the integer overflow condition to achieve privilege escalation. The attack vector requires local access and some level of authorization on the system. Successful exploitation allows an attacker to run code with system-level privileges. Patches are expected to be available through Microsoft Windows Updates.

Affected products

  • Microsoft Windows USB Video Driver Multiple versions (consult Microsoft advisory)

Timeline

  • 2026-09-08: disclosed

References