Impact
The Windows MIDI Service Module contains a flaw that can expose sensitive system information to an unauthorized control sphere. An attacker with local authorization can trigger the vulnerability to leak confidential data, potentially including operating system state or configuration details. This information disclosure is identified as CWE-497, indicating that a global resource may be used after it has been released, which compromises confidentiality.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1 are affected by this vulnerability. The issue applies to the Windows MIDI Service Module on arm64 architectures in the 24H2 and 25H2 releases, and on the x64 architecture in the 26H1 release.
Risk and Exploitability
The CVSS score of 5.5 places this vulnerability in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a current high‑profile exploit. The attack vector appears to be local: an attacker must already have authorized access to the system to read the exposed information. While remote exploitation is not documented, the presence of local privilege escalation could allow the attacker to leverage this flaw to obtain confidential system data.
OpenCVE Enrichment