Junglewise Threat Intelligence

CVE-2026-72962: Microsoft Windows USB Video Driver heap-based buffer overflow

CVE-2026-72962 · Severity: high · CVSS 8.2 · Published 2026-09-08

Executive brief

A heap-based buffer overflow vulnerability exists in the Windows USB Video Driver, a core Windows component that manages USB video device communication. An authorized local attacker could exploit this to elevate privileges and gain administrative access to the system.

Technical details

A heap-based buffer overflow flaw in the Windows USB Video Driver allows an authenticated local attacker to overflow memory buffers and execute arbitrary code with elevated privileges. The vulnerability requires prior authorization and local system access to exploit. Successful exploitation could allow an attacker to achieve privilege escalation and gain system-level control. Microsoft has issued a security patch to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats