Impact
An authorized local attacker can trigger a flaw in the Windows MIDI Service Module that exposes sensitive system information. The vulnerability lets the attacker read data that should be restricted to the control sphere of the operating system. Exposure of configuration details, user data or other privileged information could be leveraged further by the attacker to compromise additional components.
Affected Systems
Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 25H2, and Microsoft Windows 11 Version 26H1 are affected by this issue.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact for local privilege. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. The likely attack vector is a local attacker who has authorized access to the system; remote exploitation is not indicated by the description. Given the lack of publicly known exploits, the probability of immediate exploitation appears low, but the disclosed information could be valuable for subsequent attacks.
OpenCVE Enrichment