Executive brief
Windows includes a USB Video Class driver for handling video devices connected via USB. An authorized local attacker can exploit an integer overflow in this driver to gain elevated system privileges, potentially allowing unauthorized access to sensitive system resources or complete system compromise.
Technical details
The vulnerability is an integer overflow or wraparound flaw in the Windows USB Video Driver. An authenticated/authorized local attacker can trigger the integer overflow condition to achieve privilege escalation. The attack vector requires local access and some level of authorization on the system. Successful exploitation allows an attacker to run code with system-level privileges. Patches are expected to be available through Microsoft Windows Updates.
Affected products
- Microsoft Windows USB Video Driver Multiple versions (consult Microsoft advisory)
Timeline
- 2026-09-08: disclosed