Description
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Heap-based buffer overflow in the Windows MIDI Service Module allows an authorized local user to elevate privileges. The flaw is a classic out-of-bounds write (CWE-122) that can modify process memory during component initialization, potentially enabling execution of arbitrary code with higher privileges.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1 are affected. The vulnerability is present in arm64 builds for 24H2 and 25H2 and in x64 builds for 26H1. Only these specific builds are listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is not available, so the exact exploitation probability cannot be quantified. Because the attacker must already be authenticated on the local machine, the attack vector is local. It is not yet listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no public exploitation has been observed. Without a public exploit, the likelihood remains theoretical but could be realized if an attacker gains foothold and triggers the crash.

Generated by OpenCVE AI on August 12, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows 11 cumulative updates and security patches that address the MIDI Service Module vulnerability from Microsoft.
  • If a patch is not yet available, temporarily disable or stop the Windows MIDI Service Module using the Services console or Group Policy to prevent the local privilege escalation.
  • Monitor Microsoft Security Response Center for an official fix and apply it immediately when released; meanwhile, restrict local user privileges and enforce least privilege principles.

Generated by OpenCVE AI on August 12, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Title Windows MIDI Service Module Elevation of Privileges Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:49.217Z

Reserved: 2026-07-14T20:56:21.890Z

Link: CVE-2026-62688

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:38.645Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:18.397

Modified: 2026-08-13T14:49:54.717

Link: CVE-2026-62688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:22:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow