CVE-2026-69720
massMicrosoft Windows MIDI Service heap overflow enables local privilege escalation
CVE-2026-69720 is a heap-based buffer overflow (CWE-122) in the Windows MIDI Service Module, a component of Microsoft Windows. An authorized local attacker with standard (low) privileges can trigger the flaw by having the service process crafted MIDI input, with no user interaction required. Successful exploitation allows the attacker to elevate privileges on the local system, with high impact on confidentiality, integrity, and availability — effectively higher-privilege code execution on the machine. Any Windows system containing the Windows MIDI Service Module is affected, though specific affected version ranges were not provided in the available data. There is currently no known in-the-wild exploitation, no public proof-of-concept, and a low EPSS score (0.3%, 25th percentile), indicating limited near-term exploitation risk.
What to do: Install the fix from Microsoft's security advisory for CVE-2026-69720 on affected Windows systems as soon as it is published, and check the advisory for the definitive list of affected versions. Because exploitation requires an authorized local account with no user interaction, restrict local logon rights on shared or multi-user workstations as an interim measure. No active exploitation or public PoC is known, so routine patch cadence is acceptable, but prioritize patching where the bug could be chained with a remote code execution flaw.
| Microsoft Windows MIDI Service Module (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.