important · Physical — Windows
Three Windows USB and SCSI flaws let an attached device elevate privileges without login or consent.
Affects
Microsoft Windows 10, Windows 11, and Windows Server, desktop and server operating systems with USB and SCSI storage support.
The recorded primitives are two out-of-bounds reads and an untrusted-pointer dereference in kernel-mode storage and hub drivers.
Detail and 6 sources
Microsoft does not disclose the triggering descriptors or commands, or the precise privileges obtained.
Affected systems include end-of-life hardware.
Chain to watch
Attach or present a malicious USB or SCSI-class device→↓Reach an affected kernel driver with device-controlled input→↓Obtain elevated Windows privileges→↓The triggering device structures and resulting privilege level are unknown.
Unverified chainDiff the September USBSTOR, USB hub and SCSI class driver binaries, then fuzz the changed paths with instrumented USB and virtual SCSI hardware.
Sources
Researchhttps://secalerts.co/vulnerability/CVE-2026-69490ResearchCVE-2026-72999 - Vulnerability Details - OpenCVEResearchhttps://tenable.com/cve/CVE-2026-78451Researchhttps://secalerts.co/vulnerability/CVE-2026-78451ResearchZero Day Initiative — The September 2026 Security Update ReviewCVEGHSA-FJG5-3MV2-JJVP - Vulnerability-Lookup