Junglewise Threat Intelligence

CVE-2026-72953: Microsoft Windows USB Driver heap-based buffer overflow

CVE-2026-72953 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows USB Driver contains a heap buffer overflow vulnerability that allows an authenticated local attacker to execute code with elevated privileges. A malicious user with local access could exploit this to gain admin-level control over the system, potentially compromising sensitive data and system integrity.

Technical details

This is a heap-based buffer overflow vulnerability in the Windows USB Driver. The flaw allows an authorized local attacker to overflow a heap buffer, which can be leveraged to elevate privileges to SYSTEM level. The attack requires local system access and user authentication to initiate. An attacker exploiting this vulnerability could execute arbitrary code with elevated privileges, potentially leading to complete system compromise. A patch has been released by Microsoft.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats