Impact
A stack‑based buffer overflow exists in the Windows MIDI Service Module. When an attacker with local authorized access submits crafted MIDI data, the overflow corrupts the stack and causes an uncontrolled modification of execution flow. The result is that the attacker can gain elevated privileges on the affected machine, potentially allowing full system control.
Affected Systems
The flaw affects Microsoft Windows 11 on the 24H2, 25H2, and 26H1 releases, including both x64 and arm64 architectures as specified in the CPEs.
Risk and Exploitability
The CVSS score of 7.8 reflects a moderate to high severity for a local privilege escalation vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, indicating no publicly confirmed exploitation at this time. The vulnerability requires local, authorized execution and relies on the presence of the vulnerable MIDI Service Module; therefore, the attack vector is inferred to be local with a need for privileged context to trigger the overflow.
OpenCVE Enrichment