Impact
Use after free in the Windows MIDI Service Module lets a user with local access gain elevated privileges. The flaw originates from improper deallocation of memory, leading to a CWE-416 use‑after‑free vulnerability. Exploitation could enable any local attacker who can run code to perform actions with higher privileges, impacting confidentiality, integrity, and availability of the system.
Affected Systems
Microsoft Windows 11 version 24H2, 25H2, and 26H1 for ARM64 and x64 processors.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate severity, yet the EPSS score of less than 1% signals that the likelihood of exploitation observed in the wild is low. The vulnerability is not listed in the CISA KEV catalog, so no large‑scale exploitation campaigns are known at this time. The attack requires a local attacker with the ability to execute code, and the use‑after‑free can be triggered via interactions with the MIDI Service Module. Given the low EPSS and absence from KEV, the immediate risk is moderate, but the availability of a local privilege escalation means that affected users should still consider applying the vendor patch promptly.
OpenCVE Enrichment