Impact
CVE-2026-56187 is a use‑after‑free flaw in the Windows MIDI Service Module that lets a local, authorized attacker gain higher privileges on the system. The vulnerability emerges when a freed resource is accessed again, allowing the attacker to execute code with elevated rights. The impact is confinement to the local machine, where an attacker can gain capabilities beyond the attacker’s original user account.
Affected Systems
Windows 11 version 24H2, 25H2 and 26H1 are affected. The first two releases are available on ARM64 architectures and the 26H1 release on x64. Users of these editions are directly at risk if the patch is not applied.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers require local access and the capability to execute or influence a program that uses the MIDI Service Module to trigger the use‑after‑free. Once the flaw is triggered, the attacker can raise privileges to local administrator or similar elevated level within the host operating system.
OpenCVE Enrichment