CVE-2026-69339: Windows MIDI Service Module Information Disclosure Vulnerability
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
Other sources
Windows MIDI Service Module Information Disclosure Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on the affected system and able to act locally. The available information does not indicate that remote exploitation or user interaction is required.
What is the likely security impact?
Successful exploitation can disclose sensitive system information. The provided severity data indicates no stated impact to integrity or availability.
How urgent is remediation?
The vulnerability is rated medium severity with a score of 5.5. Because exploitation requires local authorized access, prioritize systems where lower-privileged local users may be present and where disclosure of system information could aid further attacks.