VDB

GCVE-110-NCSC-2026-353

GCVE-110-NCSC-2026-353
Advisory PublishedCVSS 7.8/10
Vulnetix · Advisory published September 8, 2026
A heap-based buffer overflow vulnerability in the Windows USB Mass Storage Class Driver enables unauthorized attackers to execute arbitrary code remotely over a network.

Weaknesses (CWE)

CWE-122Heap-based Buffer OverflowCWE-416Use After FreeCWE-787Out-of-bounds WriteCWE-121Stack-based Buffer OverflowCWE-1390Weak AuthenticationCWE-415Double FreeCWE-59Improper Link Resolution Before File Access ('Link Following')

Risk Scores

CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

562 records in the GCVE database · Updated September 9, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›