CVE-2026-69319: Windows USB Video Driver Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69319
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-693190.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69319 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Windows USB Video
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-72962: Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevat…nvd · 2026-09-08
- highCVE-2026-69584: Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to el…nvd · 2026-09-08
- highCVE-2026-69423: Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevat…nvd · 2026-09-08
- highCVE-2026-69422: Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges…nvd · 2026-09-08
- highCVE-2026-69319: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd · 2026-09-08
- highCVE-2026-69423: Windows USB Video Driver Elevation of Privilege Vulnerabilitymsrc · 2026-09-08
More from Microsoft Security Response Center
- mediumCVE-2026-18924: HTTP/2 server push UAF2026-09-08
- highCVE-2026-69630: Windows Win32k Elevation of Privilege Vulnerability2026-09-08
- unknownCVE-2026-83616: xmldom: Processing Instruction Target Injection Bypasses requireWellFormed2026-09-08
- unknownCVE-2026-85062: Colord: Slow rejection of oversized malformed color strings2026-09-08
- mediumCVE-2026-80834: crypto: sun8i-ce - Remove crypto_rng interface2026-09-08