Impact
The flaw arises from improper access control in the Windows MIDI Service Module. An attacker who already has local authorization can exploit this weakness to elevate their privileges to a higher local level. The vulnerability is categorized as CWE‑284, indicating a failure of access control checks. The impact is strictly local; it does not enable remote code execution or affect confidentiality of data, but it allows a user to gain elevated rights on the affected system.
Affected Systems
Microsoft Windows 11 24H2, 25H2 and 26H1 are affected. The exposure applies to both ARM64 builds of 24H2 and 25H2, and the x64 build of 26H1. The Windows MIDI Service Module is the component that implements the vulnerable access control logic.
Risk and Exploitability
The CVSS score of 8.8 places this as a high‑severity issue, yet the EPSS score of less than 1% suggests a very low likelihood of active exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires local authorization and a legitimate user context. The overall risk to an organization remains moderate, but the potential to move from a standard user to an elevated local account warrants prompt remediation.
OpenCVE Enrichment