CVE-2026-78464
massTOCTOU Race Condition in Windows MIDI Service Module Enables Local Privilege Escalation
CVE-2026-78464 is a time-of-check time-of-use (TOCTOU) race condition (CWE-367) in the Windows MIDI Service Module, disclosed by Microsoft as the CNA. It is triggered when an authorized local user wins a race between the service's validation of a resource and its subsequent use of that resource, allowing a crafted swap or replacement in between; the high attack complexity (AC:H) in the CVSS score reflects how timing-sensitive this is. A successful exploit lets an attacker with existing low-privileged local access elevate privileges on the machine, with high impact to confidentiality, integrity, and availability. Any Windows system running the affected MIDI Service module is exposed, though the specific affected version ranges are not stated in the available data and must be confirmed in Microsoft's advisory. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's fix for CVE-2026-78464 via Windows Update as soon as it is available, and confirm affected builds in the Microsoft advisory since version ranges are not in the summary data. Because the flaw requires local access with low privileges, prioritize patching multi-user workstations, terminal/RDS servers, and hosts that permit logon by untrusted or semi-trusted local accounts. With no public PoC, no KEV listing, and low EPSS, standard patch cadence is defensible, but monitor the MIDI service for unusual privilege or process activity until patched.
| Microsoft Windows MIDI Service Module | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 11 24h2, windows 11 25h2, windows 11 26h1
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.