Description
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 08 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally. | |
| Title | Windows MIDI Service Module Information Disclosure Vulnerability | |
| First Time appeared |
Microsoft
Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows 11 26h1 |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:* |
|
| Vendors & Products |
Microsoft
Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows 11 26h1 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-09-08T17:14:43.660Z
Reserved: 2026-07-31T16:47:02.144Z
Link: CVE-2026-68842
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses