PatchSiren cyber security CVE debrief
CVE-2026-58528 Microsoft CVE debrief
CVE-2026-58528 is an out-of-bounds read vulnerability in the Windows USB Audio Class driver (usbaudio.sys). The vulnerability allows an unauthorized attacker to disclose information with a physical attack. Microsoft has released a patch for this vulnerability. This vulnerability affects Windows operating systems and has a CVSS score of 6.8, classified as MEDIUM severity. System administrators and users of Windows operating systems should be aware of this vulnerability and take steps to patch their systems. The vulnerability is caused by an out-of-bounds read in the Windows USB Audio Class driver (usbaudio.sys), allowing an attacker with physical access to the system to disclose sensitive information.
- Vendor
- Microsoft
- Product
- Windows 10 Version 1809
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-20
Who should care
System administrators and users of Windows operating systems should be aware of this vulnerability and take steps to patch their systems. This vulnerability affects Windows operating systems and allows an unauthorized attacker to disclose information with a physical attack. Microsoft has released a patch for this vulnerability, and it is recommended to apply the patch as soon as possible.
Technical summary
The vulnerability is caused by an out-of-bounds read in the Windows USB Audio Class driver (usbaudio.sys). This allows an attacker with physical access to the system to disclose sensitive information. The affected product is Windows operating systems. The vulnerability has a CVSS score of 6.8 and is classified as MEDIUM severity. Microsoft has released a patch for this vulnerability, and system administrators should prioritize patching their systems.
Defensive priority
Medium
Recommended defensive actions
- Apply the patch released by Microsoft
- Ensure that all Windows operating systems are up-to-date
- Limit physical access to sensitive systems
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-14T18:18:39.360Z and was last modified on 2026-07-20T18:33:59.367Z. The NVD entry is currently Analyzed. This vulnerability affects Windows operating systems and allows an unauthorized attacker to disclose information with a physical attack. Microsoft has released a patch for this vulnerability. However, the specific details about the vulnerability, such as the affected product deployments and the operational impact, are limited. Defenders should verify the affected scope and severity based on the official advisory or CVE record.
Official resources
-
CVE-2026-58528 CVE record
CVE.org
-
CVE-2026-58528 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T18:18:39.360Z and has not been modified since then. The NVD entry is currently Analyzed.