CVE-2026-69440
massLocal Privilege Escalation via TOCTOU Race in Windows MIDI Service Module
CVE-2026-69440 is a time-of-check time-of-use (TOCTOU) race condition (CWE-367) in the Windows MIDI Service Module, a component that ships with Microsoft Windows. It is triggered when a local, low-privileged attacker times their actions to win a race between the service's security check and its use of the checked resource, with no user interaction required, though the high attack complexity means reliable exploitation is difficult. A successful race win lets an authorized but unprivileged local user elevate their privileges on the local machine, with high impact to confidentiality, integrity, and availability. Any supported Windows release running the affected MIDI Service Module is exposed, making the potential footprint effectively the entire Windows installed base. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts its 30-day exploitation probability at just 0.2% (11th percentile), so no exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-69440 via Windows Update as soon as it is available, and confirm the affected and patched version lists in Microsoft's advisory. Until patched, restrict local code execution to trusted users on multi-user Windows systems, and prioritize patching shared endpoints, VDI hosts, and servers that allow interactive logins. No public exploit exists, so routine patch-cycle prioritization is likely sufficient given the low EPSS score.
| Microsoft Windows MIDI Service Module | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.