CVE-2026-78464: Windows MIDI Service Module Elevation of Privileges Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Other sources
Windows MIDI Service Module Elevation of Privileges Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9445Patch KB5124008 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2954Patch KB5124012 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9445Patch KB5124008
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running Microsoft Windows 11 with the Windows MIDI Service Module are in scope. Exploitation is local, so remotely unauthenticated attackers are not described as able to trigger it directly.
What access does an attacker need?
The attacker must already be authorized on the affected system and have local access. User interaction is not required.
What is the likely impact if exploitation succeeds?
A successful race-condition exploit can allow the authorized local attacker to elevate privileges. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability.
Is there a workaround or detection guidance available?
The provided data does not include a workaround, mitigation, affected build information, or detection guidance. The Microsoft security advisory reference is the available source for update and remediation details.