Description
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
Published: 2026-09-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Assess Impact
AI Analysis

Impact

An authorized local attacker can trigger a flaw in the Windows MIDI Service Module that exposes sensitive system information. The vulnerability lets the attacker read data that should be restricted to the control sphere of the operating system. Exposure of configuration details, user data or other privileged information could be leveraged further by the attacker to compromise additional components.

Affected Systems

Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 25H2, and Microsoft Windows 11 Version 26H1 are affected by this issue.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate impact for local privilege. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. The likely attack vector is a local attacker who has authorized access to the system; remote exploitation is not indicated by the description. Given the lack of publicly known exploits, the probability of immediate exploitation appears low, but the disclosed information could be valuable for subsequent attacks.

Generated by OpenCVE AI on September 8, 2026 at 19:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Microsoft cumulative updates that address CVE-2026-68842 as soon as they become available
  • Disable or stop the Windows MIDI Service Module if the machine does not require MIDI functionality
  • Keep the Windows 11 system fully updated and monitor Microsoft security advisories for further guidance

Generated by OpenCVE AI on September 8, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
Title Windows MIDI Service Module Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-497
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:34:34.357Z

Reserved: 2026-07-31T16:47:02.144Z

Link: CVE-2026-68842

cve-icon Vulnrichment

Updated: 2026-09-08T18:24:08.628Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:32.160

Modified: 2026-09-16T15:06:15.950

Link: CVE-2026-68842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:03:54Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere