Skip to navigation Skip to main content Skip to footer

Technical Advisory: Microsoft Windows – MIDI Service Module Escalation of Privileges (CVE-2026-62688)

By Alex Plaskett

08 October 2026

Vendor: Microsoft    
Vendor URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688 
Versions affected: See MSRC advisory
Systems Affected: Microsoft Windows
Author: Alex Plaskett 
Risk: Medium – Local Elevation of Privilege
Methodology: Agentic Vulnerability Identification and Exploitation

 

1. Summary

The diag-loopback MIDI transport hands every client a pair of shared-memory ring buffers whose read and write positions live in a page the client also maps and controls. 

Two service routines use those positions as raw, unbounded offsets into the buffer base - giving a client an arbitrary-offset read and an arbitrary-offset write from each buffer base. The buffer bases sit at a fixed delta below the service worker thread's committed stack, and CET is off, so it is possible to plant a ROP chain over a saved return address.

A non /GS routine that parks in a 5-second wait returns straight into that chain → LoadLibraryW of an attacker DLL planted in C:\Windows\Temp → the DLL runs as LOCAL SERVICE and uses SeImpersonatePrivilege (EfsPotato) to steal a SYSTEM token, then pops a SYSTEM console onto the interactive desktop.

Exploitability of this issue can be performed from a standard user perspective. 


2. Details

  • Target service: midisrv.exe (Windows MIDI Services / Microsoft.Windows.MidiServices, the USB MIDI 2.0 stack)
  • Service identity: NT AUTHORITY\LOCAL SERVICE (holds `SeImpersonatePrivilege`)
  • Build: midisrv.exe 643,072 bytes SHA256 22D97384FD5CD5BBAD0499D94F2F78C74C1939A894D0CFEE9B453400DAD1E5E9 
  • BuildLabEx Version 29610.1000.amd64fre.rs_prerelease.260605-1837
  • Attacker: test\lowpriv - member of BUILTIN\User, no admin rights
  • Result:arbitrary code execution as LOCAL SERVICE → SYSTEM token → a visible SYSTEM `cmd.exe` on the logged-in user's desktop + SYSTEM-owned proof files
  • Mitigations on this build: CET = off, /GS cookie absent on the corrupted routine, CFG present (forward-edge only - irrelevant to a return-address hijack)

 

3. Vulnerability Details

The shared-buffer transport

The diagnostic loopback transport SWD\MIDISRV\MIDIU_DIAG_LOOPBACK_A / _B gives each connected client a pair of ring buffers:

  • MidiOut (client→service)
  • MidiIn (service→client). 


Each buffer is a 2 MB double-mapped region, and each has a small register page, mapped into the client, holding the buffer's read position and write position. 

The client is supposed to advance these as it produces/consumes MIDI bytes.

  • Two routines trust client-controlled positions as raw offsets
    OOB read - CMidiXProc::ProcessMidiIn reads MIDI bytes from MidiOut_base + readPos, taking readPos directly from the client register page with no upper bound. → arbitrary offset read.
  • OOB write - CMidiXProc::SendMidiMessageInternal memcpy`s the outgoing message to MidiIn_base + 0x10 + writePos, taking writePos directly from the client register page

The single bounds check is the relative expression as follows:

size + 0x10  <=  (readPos - writePos) – 1

Because both readPos and writePos come from the client-controlled register page, the attacker simply sets readPos = writePos + size + 0x11 and the check always passes. 

There is no absolute bound on either position, so the write destination MidiIn_base + 0x10 + writePos can be driven anywhere.

Why this reaches the stack

The two buffer bases sit at fixed, ASLR-invariant deltas below the worker thread's committed stack anchor A (they behave like hardcoded offsets on this build):

A  ==  MidiOut_base + RDOFF            RDOFF = 0x27e000
A  ==  MidiIn_base  + 0x10 + WROFF     WROFF = 0x47dff0   (MidiIn is 0x200000 below MidiOut; each buf is a 2 MB double-map)

0x47dff0 is the value proven on the 643,072-byte build. CET is off → overwriting a return address on the stack transfer’s control. CFG only guards forward edges, so a return-address hijack sidesteps it entirely.

 
4. Exploitation Details

A fully working exploit was developed, however, the details are not included in this advisory.


5. Vendor Communication

25th June 2026 – Issue reported to Microsoft
11th August 2026 – Microsoft releases update

 

6. About NCC Group


NCC Group is a global expert in cybersecurity and risk mitigation, working with businesses to protect their brand, value and reputation against the ever-evolving threat landscape. With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face. We are passionate about making the Internet safer and revolutionizing the way in which organizations think about cybersecurity.