Impact
Heap-based buffer overflow in the Windows MIDI Service Module allows an authorized local user to elevate privileges. The flaw is a classic out-of-bounds write (CWE-122) that can modify process memory during component initialization, potentially enabling execution of arbitrary code with higher privileges.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1 are affected. The vulnerability is present in arm64 builds for 24H2 and 25H2 and in x64 builds for 26H1. Only these specific builds are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is not available, so the exact exploitation probability cannot be quantified. Because the attacker must already be authenticated on the local machine, the attack vector is local. It is not yet listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no public exploitation has been observed. Without a public exploit, the likelihood remains theoretical but could be realized if an attacker gains foothold and triggers the crash.
OpenCVE Enrichment