CVE-2026-69491
massHeap overflow in Microsoft DirectMusic allows unauthenticated network RCE
CVE-2026-69491 is a heap-based buffer overflow (CWE-122) in Microsoft DirectMusic, the DirectX audio/MIDI component bundled with Windows. According to the description and CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw can be triggered by an unauthenticated attacker over a network with no user interaction required. Successful exploitation allows arbitrary code execution, with high confidentiality, integrity, and availability impacts, earning a critical 9.8 CVSS score. Anyone running Windows deployments that include the vulnerable DirectMusic component is potentially affected, though the provided data does not specify exact affected Windows versions or builds. Exploitation status: no public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and EPSS assigns only a 0.9% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Install Microsoft's security update for CVE-2026-69491 via Windows Update as soon as it is available and check Microsoft's advisory for the exact affected Windows builds, since version ranges are not included in the provided data. Until systems are patched, prioritize them for remediation given the critical, network-exploitable 9.8 score, and monitor for emerging public proof-of-concept code or KEV listing.
| Microsoft Windows (Microsoft DirectMusic component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.