Description
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises from improper access control in the Windows MIDI Service Module. An attacker who already has local authorization can exploit this weakness to elevate their privileges to a higher local level. The vulnerability is categorized as CWE‑284, indicating a failure of access control checks. The impact is strictly local; it does not enable remote code execution or affect confidentiality of data, but it allows a user to gain elevated rights on the affected system.

Affected Systems

Microsoft Windows 11 24H2, 25H2 and 26H1 are affected. The exposure applies to both ARM64 builds of 24H2 and 25H2, and the x64 build of 26H1. The Windows MIDI Service Module is the component that implements the vulnerable access control logic.

Risk and Exploitability

The CVSS score of 8.8 places this as a high‑severity issue, yet the EPSS score of less than 1% suggests a very low likelihood of active exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires local authorization and a legitimate user context. The overall risk to an organization remains moderate, but the potential to move from a standard user to an elevated local account warrants prompt remediation.

Generated by OpenCVE AI on July 31, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update that addresses CVE‑2026‑50342, available from the provided MSRC link.
  • If the update cannot be applied immediately, disable or uninstall the Windows MIDI Service Module on systems where it is not required to reduce the attack surface.
  • Enforce least privilege and ensure that local user accounts have only the permissions they need, mitigating the effect of any future elevation attempts.

Generated by OpenCVE AI on July 31, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Title Windows MIDI Service Module Elevation of Privileges Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-284
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:23:45.545Z

Reserved: 2026-06-04T18:15:10.952Z

Link: CVE-2026-50342

cve-icon Vulnrichment

Updated: 2026-07-15T16:19:26.575Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:00:07Z

Weaknesses