ZeroHour

CVE-2026-69491

mass

Heap overflow in Microsoft DirectMusic allows unauthenticated network RCE

CVSS 3.1
9.8 critical
EPSS
<1%p57
Published
()
Modified
AI analysis

CVE-2026-69491 is a heap-based buffer overflow (CWE-122) in Microsoft DirectMusic, the DirectX audio/MIDI component bundled with Windows. According to the description and CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw can be triggered by an unauthenticated attacker over a network with no user interaction required. Successful exploitation allows arbitrary code execution, with high confidentiality, integrity, and availability impacts, earning a critical 9.8 CVSS score. Anyone running Windows deployments that include the vulnerable DirectMusic component is potentially affected, though the provided data does not specify exact affected Windows versions or builds. Exploitation status: no public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and EPSS assigns only a 0.9% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Install Microsoft's security update for CVE-2026-69491 via Windows Update as soon as it is available and check Microsoft's advisory for the exact affected Windows builds, since version ranges are not included in the provided data. Until systems are patched, prioritize them for remediation given the critical, network-exploitable 9.8 score, and monitor for emerging public proof-of-concept code or KEV listing.

Affected
Microsoft Windows (Microsoft DirectMusic component)
Estimated exposure
masshundreds of millions of Windows installations (DirectMusic is a bundled Windows/DirectX component) — Because DirectMusic ships with Windows, potential exposure scales with the roughly 1.4-billion-device Windows install base, though the subset actually reachable over the network is unknown given the absence of affected-version ranges.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.