ZeroHour

CVE-2026-78464

mass

TOCTOU Race Condition in Windows MIDI Service Module Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-78464 is a time-of-check time-of-use (TOCTOU) race condition (CWE-367) in the Windows MIDI Service Module, disclosed by Microsoft as the CNA. It is triggered when an authorized local user wins a race between the service's validation of a resource and its subsequent use of that resource, allowing a crafted swap or replacement in between; the high attack complexity (AC:H) in the CVSS score reflects how timing-sensitive this is. A successful exploit lets an attacker with existing low-privileged local access elevate privileges on the machine, with high impact to confidentiality, integrity, and availability. Any Windows system running the affected MIDI Service module is exposed, though the specific affected version ranges are not stated in the available data and must be confirmed in Microsoft's advisory. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's fix for CVE-2026-78464 via Windows Update as soon as it is available, and confirm affected builds in the Microsoft advisory since version ranges are not in the summary data. Because the flaw requires local access with low privileges, prioritize patching multi-user workstations, terminal/RDS servers, and hosts that permit logon by untrusted or semi-trusted local accounts. With no public PoC, no KEV listing, and low EPSS, standard patch cadence is defensible, but monitor the MIDI service for unusual privilege or process activity until patched.

Affected
Microsoft Windows MIDI Service Module
Estimated exposure
masshundreds of millions of Windows devices potentially affected (MIDI service is an inbox Windows component) — The MIDI service ships as part of the Windows platform, which runs on well over a billion devices worldwide, so even the subset of installs running the affected module plausibly exceeds 1M systems; exact coverage is unknown without…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 11 24h2, windows 11 25h2, windows 11 26h1
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.