Description
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-56187 is a use‑after‑free flaw in the Windows MIDI Service Module that lets a local, authorized attacker gain higher privileges on the system. The vulnerability emerges when a freed resource is accessed again, allowing the attacker to execute code with elevated rights. The impact is confinement to the local machine, where an attacker can gain capabilities beyond the attacker’s original user account.

Affected Systems

Windows 11 version 24H2, 25H2 and 26H1 are affected. The first two releases are available on ARM64 architectures and the 26H1 release on x64. Users of these editions are directly at risk if the patch is not applied.

Risk and Exploitability

The CVSS score of 7 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers require local access and the capability to execute or influence a program that uses the MIDI Service Module to trigger the use‑after‑free. Once the flaw is triggered, the attacker can raise privileges to local administrator or similar elevated level within the host operating system.

Generated by OpenCVE AI on July 31, 2026 at 06:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows security update from Microsoft that addresses CVE-2026-56187.
  • If the MIDI Service Module is not required, consider disabling or uninstalling it to reduce the attack surface.
  • Restrict privileged actions to trusted users and applications to minimize the chance that an authorized attacker can exploit the kernel module.

Generated by OpenCVE AI on July 31, 2026 at 06:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Title Windows MIDI Service Module Elevation of Privileges Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:26:57.242Z

Reserved: 2026-06-19T13:54:04.006Z

Link: CVE-2026-56187

cve-icon Vulnrichment

Updated: 2026-07-14T18:54:44.363Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:45:03Z

Weaknesses