Description
Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A stack‑based buffer overflow exists in the Windows MIDI Service Module. When an attacker with local authorized access submits crafted MIDI data, the overflow corrupts the stack and causes an uncontrolled modification of execution flow. The result is that the attacker can gain elevated privileges on the affected machine, potentially allowing full system control.

Affected Systems

The flaw affects Microsoft Windows 11 on the 24H2, 25H2, and 26H1 releases, including both x64 and arm64 architectures as specified in the CPEs.

Risk and Exploitability

The CVSS score of 7.8 reflects a moderate to high severity for a local privilege escalation vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, indicating no publicly confirmed exploitation at this time. The vulnerability requires local, authorized execution and relies on the presence of the vulnerable MIDI Service Module; therefore, the attack vector is inferred to be local with a need for privileged context to trigger the overflow.

Generated by OpenCVE AI on September 8, 2026 at 22:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Windows update that addresses CVE-2026-69508 from Microsoft Security Response Center.
  • Reboot the system after applying the update to ensure the fix is loaded.
  • As a temporary measure, disable the Windows MIDI Service or restrict its execution until the update is applied.

Generated by OpenCVE AI on September 8, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Title Windows MIDI Service Module Elevation of Privileges Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-121
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:42.791Z

Reserved: 2026-08-03T21:09:40.781Z

Link: CVE-2026-69508

cve-icon Vulnrichment

Updated: 2026-09-09T09:57:17.787Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:17.993

Modified: 2026-09-23T20:02:38.527

Link: CVE-2026-69508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:59:29Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow