VDB
GCVE-110-NCSC-2026-353
GCVE-110-NCSC-2026-353
Advisory PublishedCVSS 7.8/10
A heap-based buffer overflow vulnerability in the Windows USB Mass Storage Class Driver enables unauthorized attackers to execute arbitrary code remotely over a network.
Weaknesses (CWE)
CWE-122Heap-based Buffer OverflowCWE-416Use After FreeCWE-787Out-of-bounds WriteCWE-121Stack-based Buffer OverflowCWE-1390Weak AuthenticationCWE-415Double FreeCWE-59Improper Link Resolution Before File Access ('Link Following')
Risk Scores
CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | vers:unknown/* | — | — |
Aliases
CVE-2026-68839CVE-2026-69276CVE-2026-69431CVE-2026-69434CVE-2026-69463CVE-2026-69493CVE-2026-69496CVE-2026-69525CVE-2026-69579CVE-2026-69590CVE-2026-69595CVE-2026-69669CVE-2026-69715CVE-2026-69730CVE-2026-69768CVE-2026-69769CVE-2026-69819CVE-2026-69824CVE-2026-69829CVE-2026-69845CVE-2026-69910CVE-2026-70296CVE-2026-72979CVE-2026-72982CVE-2026-72983CVE-2026-73009CVE-2026-73010CVE-2026-73025CVE-2026-77493CVE-2026-78445CVE-2026-81963CVE-2026-85880
References
Browse GCVE Records
562 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.