CVE-2026-68839

9.8

Microsoft · Windows

A heap-based buffer overflow in the Windows USB Mass Storage Class Driver allows an unauthenticated, remote attacker to execute arbitrary code.

Executive summary

A critical heap-based buffer overflow vulnerability in the Windows USB Mass Storage Class Driver allows unauthenticated remote code execution, posing a severe threat to all affected systems.

Vulnerability

This is a heap-based buffer overflow (CWE-122) resulting from improper input validation (CWE-20) in the USB Mass Storage Class Driver. An unauthenticated attacker can trigger this flaw over a network to achieve remote code execution.

Business impact

The CVSS score of 9.8 reflects the high probability of successful exploitation due to the lack of required authentication and the critical impact of remote code execution. Successful exploitation allows an attacker to take full control of the affected system, leading to data exfiltration, total loss of confidentiality, integrity, and availability, and potential lateral movement within the network.

Remediation

Immediate Action: Apply the vendor-provided security updates immediately to bring all affected Windows versions to their respective fixed builds (e.g., 10.0.14393.9512 for Windows 10 1607 and 10.0.22631.7582 for Windows 11 23H2).

Proactive Monitoring: Review system and security logs for anomalous crashes in the USB driver stack or unexpected network traffic directed at storage-related services.

Compensating Controls: Utilize a network-based firewall or Intrusion Prevention System to restrict access to SMB and other storage-related protocols from untrusted network segments until patches are applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this remote code execution vulnerability, organizations must prioritize the deployment of the Microsoft security updates across all affected Windows environments. Do not delay patching, as the combination of remote access and high-privilege code execution makes this an ideal target for malicious actors.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources