Description
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in the Windows MIDI Service Module. An attacker who is authenticated on the machine can trigger the overflow and elevate their local privileges to a higher level. This flaw allows memory corruption that can lead to arbitrary code execution with increased authority on the affected system.

Affected Systems

Microsoft Windows 11 builds 24H2, 25H2, and 26H1 are affected. The flaw exists in the ARM64 versions of 24H2 and 25H2 and the x86‑64 version of 26H1, impacting both ARM64 and x86‑64 architectures.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, so the precise likelihood of exploitation is unknown, but the flaw is local and requires authentication. Although the vulnerability is not listed in the CISA KEV catalog, its potential to grant elevated privileges makes it a critical risk in environments where users can run untrusted applications that interface with the MIDI Service Module. The nature of the heap overflow means that an attacker could craft a malicious MIDI file or trigger the service programmatically to exploit the vulnerability.

Generated by OpenCVE AI on September 8, 2026 at 23:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Windows update that addresses CVE-2026-69720.
  • Reboot the computer after installing the update to ensure the patched MIDI Service Module is loaded.
  • Keep an eye on the system for any anomalous behavior of the MIDI Service Module or unexpected privilege changes.

Generated by OpenCVE AI on September 8, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Title Windows MIDI Service Module Elevation of Privileges Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:36:04.045Z

Reserved: 2026-08-03T21:35:55.263Z

Link: CVE-2026-69720

cve-icon Vulnrichment

Updated: 2026-09-09T09:56:31.486Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:44.137

Modified: 2026-09-22T16:53:15.520

Link: CVE-2026-69720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:57:25Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow