Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has released fixes for CVE-2026-72999, Windows USB Hub Driver Elevation of Privilege Vulnerability, an Important-severity flaw affecting a broad range of supported Windows client and server releases. The vulnerability is an out-of-bounds read in the Windows USB Hub Driver, tracked as CWE-125. Microsoft says an unauthorized attacker could elevate privileges through a physical attack.

The practical risk is not a drive-by web attack or a malicious attachment arriving by email. Microsoft’s advisory states that an attacker needs physical access to the target computer to plug in a malicious USB device. If successfully exploited, the attacker could gain SYSTEM privileges—the highest level of authority on a Windows machine. In short: a hostile USB device is still a bad surprise, even when it is not pretending to be a keyboard with a suspiciously enthusiastic résumé.

CVE-2026-72999 at a glance​

  • CVE: CVE-2026-72999
  • Title: Windows USB Hub Driver Elevation of Privilege Vulnerability
  • Severity: Important
  • CVSS base score: 6.8
  • CVSS temporal score: 5.9
  • CVSS vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • Weakness: CWE-125
  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes
  • Microsoft exploitation assessment: Exploitation Less Likely

Microsoft describes the issue as follows: “Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.”

The Physical attack vector is important context for administrators prioritizing patch deployment. Microsoft explains that the attacker must have physical access to connect a malicious USB device. That makes workstation controls—such as locked offices, device-port policies, controlled visitor access, and restrictions on unknown peripherals—useful layers of defense, but they are not substitutes for installing the security updates.

Why SYSTEM-level access matters​

Privilege-escalation flaws are often a second-stage problem: an attacker may first need access to the computer, then use a vulnerability to obtain greater control. In this case, the advisory’s physical-access condition narrows the attack scenario, while the potential outcome remains severe for an affected device.

SYSTEM privileges can allow an attacker to operate beyond the restrictions of a standard user account. For enterprise teams, the priority should be systems exposed to shared physical access: reception-area PCs, meeting-room devices, lab machines, kiosks, field laptops, and servers where USB ports are accessible during maintenance.

Affected Windows releases and fixed builds​

Microsoft has provided updates for Windows 10, Windows 11, and Windows Server editions. Administrators should deploy the matching KB for each installed release and confirm that devices reach the listed fixed build.

Windows 10​

  • For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

Windows 11​

  • For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

Windows Server​

  • For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
  • For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

What administrators should do​

Because Microsoft marks customer action as required, organizations should identify affected endpoints and servers, deploy the appropriate cumulative update, and verify the resulting OS build in their update-management reporting.

Prioritize systems with accessible USB ports and a meaningful chance of unsupervised physical contact. That includes shared or public-facing Windows devices, laptops that travel, systems in branch offices, and server environments where contractors or multiple operational teams may have console access.

The key operational takeaway is straightforward: physical access is a meaningful barrier, not a magical force field. Apply the relevant Windows security update, confirm the fixed build, and keep unknown USB hardware out of machines that matter.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com