CVE-2026-72962 – Windows USB Video Driver Elevation of Privilege Vulnerability
CVSS 8.2
IMPORTANT
Critical - Same Day Deployment
“A successful attack can turn existing local access into powerful VTL1 privileges, putting critical system security boundaries at risk.”
CVE-2026-72962 is a heap-based buffer overflow in the Windows USB Video Driver. An authenticated local attacker can send specially crafted requests to the affected USB video component and, if successful, cross a security boundary and gain elevated Virtual Trust Level 1 (VTL1) privileges. No user interaction is required, although exploitation requires high privileges.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-122
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.