Impact
The vulnerability is a heap-based buffer overflow in the Windows MIDI Service Module. An attacker who is authenticated on the machine can trigger the overflow and elevate their local privileges to a higher level. This flaw allows memory corruption that can lead to arbitrary code execution with increased authority on the affected system.
Affected Systems
Microsoft Windows 11 builds 24H2, 25H2, and 26H1 are affected. The flaw exists in the ARM64 versions of 24H2 and 25H2 and the x86‑64 version of 26H1, impacting both ARM64 and x86‑64 architectures.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, so the precise likelihood of exploitation is unknown, but the flaw is local and requires authentication. Although the vulnerability is not listed in the CISA KEV catalog, its potential to grant elevated privileges makes it a critical risk in environments where users can run untrusted applications that interface with the MIDI Service Module. The nature of the heap overflow means that an attacker could craft a malicious MIDI file or trigger the service programmatically to exploit the vulnerability.
OpenCVE Enrichment