Executive brief
Windows USB Driver contains a heap buffer overflow vulnerability that allows an authenticated local attacker to execute code with elevated privileges. A malicious user with local access could exploit this to gain admin-level control over the system, potentially compromising sensitive data and system integrity.
Technical details
This is a heap-based buffer overflow vulnerability in the Windows USB Driver. The flaw allows an authorized local attacker to overflow a heap buffer, which can be leveraged to elevate privileges to SYSTEM level. The attack requires local system access and user authentication to initiate. An attacker exploiting this vulnerability could execute arbitrary code with elevated privileges, potentially leading to complete system compromise. A patch has been released by Microsoft.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed