CVE-2026-72962 – Windows USB Video Driver Elevation of Privilege Vulnerability

CVSS 8.2 IMPORTANT Critical - Same Day Deployment

“A successful attack can turn existing local access into powerful VTL1 privileges, putting critical system security boundaries at risk.”

CVE-2026-72962 is a heap-based buffer overflow in the Windows USB Video Driver. An authenticated local attacker can send specially crafted requests to the affected USB video component and, if successful, cross a security boundary and gain elevated Virtual Trust Level 1 (VTL1) privileges. No user interaction is required, although exploitation requires high privileges.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.