Junglewise Threat Intelligence

CVE-2026-56187: Microsoft Windows MIDI Service Module use after free privilege escalation

CVE-2026-56187 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows MIDI Service, which handles musical instrument digital interface data on Windows 11 systems. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the device. This could allow them to install malicious software, view or delete sensitive data, or disrupt business operations.

Technical details

A use-after-free (CWE-416) vulnerability exists within the Windows MIDI Service Module. The flaw is triggered when the service incorrectly manages memory during the processing of MIDI data, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must have local access to the system with low-level privileges and successfully win a race condition or navigate high complexity execution paths (AC:H). Successful exploitation allows the attacker to execute code with elevated system privileges. Microsoft has released security updates to address this issue across affected Windows 11 versions.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.26200.0 to 10.0.28000.2525

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats