CVE-2026-69508: Windows MIDI Service Module Elevation of Privileges Vulnerability
Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Other sources
Windows MIDI Service Module Elevation of Privileges Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2954Patch KB5124012
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on the affected system and have local access. The issue affects Microsoft Windows 11 systems with the Windows MIDI Service Module.
What level of access could exploitation provide?
Successful exploitation can allow a locally authorized attacker to elevate privileges. The listed impact includes high confidentiality, integrity, and availability effects.
Is user interaction required for exploitation?
No user interaction is required according to the provided vector. Exploitation has low attack complexity but requires local access and low privileges.