Executive brief
The Windows MIDI Service Module contains a vulnerability that allows authorized users with local access to read sensitive system information they should not be able to access. While this requires local presence and valid credentials, successful exploitation could expose confidential data that might be used in follow-up attacks or compromise system integrity.
Technical details
The vulnerability is classified as exposure of sensitive system information to an unauthorized control sphere, allowing an authorized local attacker to disclose information through the Windows MIDI Service Module. The flaw requires local access and valid authentication to trigger. An attacker with these preconditions can read sensitive system data that should be restricted. The vulnerability does not appear to be actively exploited in the wild, and patches are available from Microsoft Security Response Center.
Affected products
- Microsoft Windows multiple
Timeline
- 2026-09-08: disclosed