Impact
A time‑of‑check time‑of‑use race condition exists in the Windows MIDI Service Module. The flaw enables an attacker who already has local access to obtain higher privileges on the system. The vulnerability is classified as CWE-367.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2 and 26H1 are affected. The first two are available on ARM64, while version 26H1 is on x64 architecture.
Risk and Exploitability
The CVSS score is 7, indicating a moderate‑to‑high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to run locally on the target system and to induce a race condition with the MIDI service; thus the attack vector is likely local only. Because the flaw allows privilege escalation, it poses a significant risk to confidentiality, integrity, and availability of the affected systems if an attacker can execute code with elevated rights.
OpenCVE Enrichment