CVE-2026-62693: Windows MIDI Service Module Elevation of Privileges Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Other sources
Windows MIDI Service Module Elevation of Privileges Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26100.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2704Patch KB5121000 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9168Fixed in 10.0.26100.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26000.9106Patch KB5120994
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62693?
The severity of CVE-2026-62693 is rated as high with a score of 7.
How do I fix CVE-2026-62693?
To fix CVE-2026-62693, ensure that your Microsoft Windows 11 is updated with the latest security patches released by Microsoft.
What type of vulnerability is CVE-2026-62693?
CVE-2026-62693 is a race condition vulnerability that affects the Windows MIDI Service Module.
Who can be affected by CVE-2026-62693?
CVE-2026-62693 can be exploited by an authorized attacker with local access to elevate their privileges.
What does CVE-2026-62693 allow an attacker to do?
CVE-2026-62693 allows an attacker to elevate privileges locally on affected Microsoft Windows systems.