Executive brief
Windows includes a USB Hub Driver component that manages communication with USB devices connected to a computer. A flaw in this driver could allow an attacker with physical access to a USB port to read data from memory and potentially gain elevated privileges on the system.
Technical details
An out-of-bounds read vulnerability exists in the Windows USB Hub Driver that can be triggered through a specially crafted USB device. The vulnerability requires physical access to a USB port to exploit. An attacker with physical access could leverage this to read sensitive memory contents and potentially escalate privileges on the affected system. The attack vector is physical, limiting exposure to systems where an attacker has direct hardware access.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed