Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has released fixes for CVE-2026-69571, an Important Windows privilege-escalation flaw in the Windows USB Audio Class driver, usbaudio.sys. The issue spans a notably broad set of supported Windows client and server releases, including Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025, and Server Core installations.

Abstract illustration of connected devices separated by a protected security boundary. CVE-2026-69571 at a glance​

Exact title: Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability

Severity: Important

CVSS base score: 7.8

CVSS temporal score: 6.8

CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

CWE: CWE-122

Microsoft describes the vulnerability as follows:

“Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability: Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.”

The underlying weakness is a heap-based buffer overflow, classified as CWE-122. In practical terms, an attacker must already be authorized on the affected device, but Microsoft says a successful exploit could result in the highest local privilege level.

“What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”

That distinction matters. This is not described as a remote-code-execution bug, and the CVSS vector specifies local access (AV:L) plus existing privileges (PR:L). However, the potential outcome—SYSTEM privileges—makes it a meaningful post-compromise risk. An attacker who has already gained a foothold as a standard user could potentially turn that beachhead into full control of the PC or server. In security terms, this is the second act of the break-in, and it is rarely the act administrators want to leave unpatched.

Publicly disclosed: No
Exploited: No
Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation Less Likely.

What Windows administrators should do​

Deploy the applicable cumulative update for every affected Windows build in the environment, then verify that systems report the corresponding fixed OS build. The following mappings are Microsoft’s specified remediation targets.

Affected productRequired updateFixed build
Windows 10 Version 1607 for 32-bit Systems (x86)KB512309910.0.14393.9512
Windows 10 Version 1607 for x64-based SystemsKB512309910.0.14393.9512
Windows 10 Version 1809 for 32-bit Systems (x86)KB512287610.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsKB512287610.0.17763.9245
Windows 10 Version 21H2 for 32-bit Systems (x86)KB512287810.0.19044.7725
Windows 10 Version 21H2 for ARM64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 21H2 for x64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 22H2 for 32-bit Systems (x86)KB512287810.0.19045.7725
Windows 10 Version 22H2 for ARM64-based SystemsKB512287810.0.19045.7725
Windows 10 Version 22H2 for x64-based SystemsKB512287810.0.19045.7725
Windows 11 Version 23H2 for ARM64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 25H2 for ARM64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 26H1 for ARM64-based SystemsKB512401210.0.28000.2954
Windows 11 version 26H1 for x64-based SystemsKB512401210.0.28000.2954
Windows Server 2012 (Server Core installation) (x64)KB51230656.2.9200.26349
Windows Server 2012 (x64)KB51230656.2.9200.26349
Windows Server 2012 R2 (Server Core installation) (x64)KB51230666.3.9600.23398
Windows Server 2012 R2 (x64)KB51230666.3.9600.23398
Windows Server 2016 (Server Core installation) (x64)KB512309910.0.14393.9512
Windows Server 2016 (x64)KB512309910.0.14393.9512
Windows Server 2019 (Server Core installation) (x64)KB512287610.0.17763.9245
Windows Server 2019 (x64)KB512287610.0.17763.9245
Windows Server 2022 (Server Core installation) (x64)KB512288210.0.20348.5622
Windows Server 2022 (x64)KB512288210.0.20348.5622
Windows Server 2025 (Server Core installation) (x64)KB512287110.0.26100.33438
Windows Server 2025 (x64)KB512287110.0.26100.33438

Remediation instructions by platform​

For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725. For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.

For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725. For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582. For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.

For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445. For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.

For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445. For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.

For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954. For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349. For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.

For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398. For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.

For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512. For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.

For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245. For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.

For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622. For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.

For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438. For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Practical priority​

CVE-2026-69571 should be prioritized in normal patch deployment because it affects a kernel-level Windows driver and can yield SYSTEM privileges after local access has been established. Organizations should include workstations, ARM64 devices, traditional x64 endpoints, Windows Server systems, and Server Core deployments in their update inventory.

The useful verification point is not merely whether a KB appears in an update history: confirm that each device reaches the Microsoft-specified fixed build for its exact Windows release. That final build check is where patch management stops being optimistic and starts being security.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com