ZeroHour

CVE-2026-69720

mass

Microsoft Windows MIDI Service heap overflow enables local privilege escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69720 is a heap-based buffer overflow (CWE-122) in the Windows MIDI Service Module, a component of Microsoft Windows. An authorized local attacker with standard (low) privileges can trigger the flaw by having the service process crafted MIDI input, with no user interaction required. Successful exploitation allows the attacker to elevate privileges on the local system, with high impact on confidentiality, integrity, and availability — effectively higher-privilege code execution on the machine. Any Windows system containing the Windows MIDI Service Module is affected, though specific affected version ranges were not provided in the available data. There is currently no known in-the-wild exploitation, no public proof-of-concept, and a low EPSS score (0.3%, 25th percentile), indicating limited near-term exploitation risk.

What to do: Install the fix from Microsoft's security advisory for CVE-2026-69720 on affected Windows systems as soon as it is published, and check the advisory for the definitive list of affected versions. Because exploitation requires an authorized local account with no user interaction, restrict local logon rights on shared or multi-user workstations as an interim measure. No active exploitation or public PoC is known, so routine patch cadence is acceptable, but prioritize patching where the bug could be chained with a remote code execution flaw.

Affected
Microsoft Windows MIDI Service Module (Windows component)
Estimated exposure
mass≈1 billion+ Windows installations (in-box OS component; presence-based, not network-exposed) — Basis: Microsoft's publicly stated Windows active install base is on the order of 1.4 billion devices, and the MIDI Service Module ships in-box with supported Windows releases, so it is plausibly present on most Windows endpoints and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.