ZeroHour

CVE-2026-69440

mass

Local Privilege Escalation via TOCTOU Race in Windows MIDI Service Module

CVSS 3.1
7.0 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-69440 is a time-of-check time-of-use (TOCTOU) race condition (CWE-367) in the Windows MIDI Service Module, a component that ships with Microsoft Windows. It is triggered when a local, low-privileged attacker times their actions to win a race between the service's security check and its use of the checked resource, with no user interaction required, though the high attack complexity means reliable exploitation is difficult. A successful race win lets an authorized but unprivileged local user elevate their privileges on the local machine, with high impact to confidentiality, integrity, and availability. Any supported Windows release running the affected MIDI Service Module is exposed, making the potential footprint effectively the entire Windows installed base. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts its 30-day exploitation probability at just 0.2% (11th percentile), so no exploitation is known.

What to do: Apply Microsoft's security update for CVE-2026-69440 via Windows Update as soon as it is available, and confirm the affected and patched version lists in Microsoft's advisory. Until patched, restrict local code execution to trusted users on multi-user Windows systems, and prioritize patching shared endpoints, VDI hosts, and servers that allow interactive logins. No public exploit exists, so routine patch-cycle prioritization is likely sufficient given the low EPSS score.

Affected
Microsoft Windows MIDI Service Module
Estimated exposure
masshundreds of millions of Windows 10/11 devices (Windows installed base ≈1.4B active devices) — The Windows MIDI Service is a built-in Windows component, so the potential install base tracks the overall Windows 10/11 installed base, which Microsoft has cited at roughly 1.4 billion active devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.