Description
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use after free in the Windows MIDI Service Module lets a user with local access gain elevated privileges. The flaw originates from improper deallocation of memory, leading to a CWE-416 use‑after‑free vulnerability. Exploitation could enable any local attacker who can run code to perform actions with higher privileges, impacting confidentiality, integrity, and availability of the system.

Affected Systems

Microsoft Windows 11 version 24H2, 25H2, and 26H1 for ARM64 and x64 processors.

Risk and Exploitability

The CVSS score of 7.0 indicates moderate severity, yet the EPSS score of less than 1% signals that the likelihood of exploitation observed in the wild is low. The vulnerability is not listed in the CISA KEV catalog, so no large‑scale exploitation campaigns are known at this time. The attack requires a local attacker with the ability to execute code, and the use‑after‑free can be triggered via interactions with the MIDI Service Module. Given the low EPSS and absence from KEV, the immediate risk is moderate, but the availability of a local privilege escalation means that affected users should still consider applying the vendor patch promptly.

Generated by OpenCVE AI on July 31, 2026 at 06:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest security update for Windows 11 (24H2, 25H2, and 26H1) from Microsoft, which fixes the use‑after‑free flaw in the MIDI Service Module.
  • Keep Windows Update notifications enabled and apply updates as soon as they become available to ensure the system has the latest security hardening.
  • If you cannot apply the update immediately, temporarily disable the Windows MIDI Service through the Services console until the patch is installed.

Generated by OpenCVE AI on July 31, 2026 at 06:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Title Windows MIDI Service Module Elevation of Privileges Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:26:55.584Z

Reserved: 2026-06-19T13:54:04.005Z

Link: CVE-2026-56183

cve-icon Vulnrichment

Updated: 2026-07-15T13:06:37.194Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:45:03Z

Weaknesses