CVE-2026-58528: Windows USB Audio Class Driver Information Disclosure Vulnerability
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
Other sources
Windows USB Audio Class Driver Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9020Patch KB5099538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5386Patch KB5099540 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650
Event History
Frequently Asked Questions
Which Windows platforms are listed as affected?
The affected software list includes Windows 10 (including versions 1809, 21H2, and 22H2), Windows 11, Windows Server 2019, Windows Server 2022, and Windows Server 2025.
Are Windows Server deployments in scope?
Yes. Windows Server 2019, Windows Server 2022, and Windows Server 2025 are included in the affected software list.
What level of access does an attacker need?
Exploitation requires a physical attack. The vulnerability is described as allowing an unauthorized attacker to disclose information through an out-of-bounds read in usbaudio.sys.