Vendor: Microsoft
Vendor URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688
Versions affected: See MSRC advisory
Systems Affected: Microsoft Windows
Author: Alex Plaskett
Risk: Medium – Local Elevation of Privilege
Methodology: Agentic Vulnerability Identification and Exploitation
1. Summary
The diag-loopback MIDI transport hands every client a pair of shared-memory ring buffers whose read and write positions live in a page the client also maps and controls.
Two service routines use those positions as raw, unbounded offsets into the buffer base - giving a client an arbitrary-offset read and an arbitrary-offset write from each buffer base. The buffer bases sit at a fixed delta below the service worker thread's committed stack, and CET is off, so it is possible to plant a ROP chain over a saved return address.
A non /GS routine that parks in a 5-second wait returns straight into that chain → LoadLibraryW of an attacker DLL planted in C:\Windows\Temp → the DLL runs as LOCAL SERVICE and uses SeImpersonatePrivilege (EfsPotato) to steal a SYSTEM token, then pops a SYSTEM console onto the interactive desktop.
Exploitability of this issue can be performed from a standard user perspective.
2. Details
- Target service: midisrv.exe (Windows MIDI Services / Microsoft.Windows.MidiServices, the USB MIDI 2.0 stack)
- Service identity: NT AUTHORITY\LOCAL SERVICE (holds `SeImpersonatePrivilege`)
- Build: midisrv.exe 643,072 bytes SHA256 22D97384FD5CD5BBAD0499D94F2F78C74C1939A894D0CFEE9B453400DAD1E5E9
- BuildLabEx Version 29610.1000.amd64fre.rs_prerelease.260605-1837
- Attacker: test\lowpriv - member of BUILTIN\User, no admin rights
- Result:arbitrary code execution as LOCAL SERVICE → SYSTEM token → a visible SYSTEM `cmd.exe` on the logged-in user's desktop + SYSTEM-owned proof files
- Mitigations on this build: CET = off, /GS cookie absent on the corrupted routine, CFG present (forward-edge only - irrelevant to a return-address hijack)
3. Vulnerability Details
The shared-buffer transport
The diagnostic loopback transport SWD\MIDISRV\MIDIU_DIAG_LOOPBACK_A / _B gives each connected client a pair of ring buffers:
- MidiOut (client→service)
- MidiIn (service→client).
Each buffer is a 2 MB double-mapped region, and each has a small register page, mapped into the client, holding the buffer's read position and write position.
The client is supposed to advance these as it produces/consumes MIDI bytes.
- Two routines trust client-controlled positions as raw offsets
OOB read - CMidiXProc::ProcessMidiIn reads MIDI bytes from MidiOut_base + readPos, taking readPos directly from the client register page with no upper bound. → arbitrary offset read. - OOB write - CMidiXProc::SendMidiMessageInternal memcpy`s the outgoing message to MidiIn_base + 0x10 + writePos, taking writePos directly from the client register page
The single bounds check is the relative expression as follows:
size + 0x10 <= (readPos - writePos) – 1
Because both readPos and writePos come from the client-controlled register page, the attacker simply sets readPos = writePos + size + 0x11 and the check always passes.
There is no absolute bound on either position, so the write destination MidiIn_base + 0x10 + writePos can be driven anywhere.
Why this reaches the stack
The two buffer bases sit at fixed, ASLR-invariant deltas below the worker thread's committed stack anchor A (they behave like hardcoded offsets on this build):
A == MidiOut_base + RDOFF RDOFF = 0x27e000A == MidiIn_base + 0x10 + WROFF WROFF = 0x47dff0 (MidiIn is 0x200000 below MidiOut; each buf is a 2 MB double-map)
0x47dff0 is the value proven on the 643,072-byte build. CET is off → overwriting a return address on the stack transfer’s control. CFG only guards forward edges, so a return-address hijack sidesteps it entirely.
4. Exploitation Details
A fully working exploit was developed, however, the details are not included in this advisory.
5. Vendor Communication
25th June 2026 – Issue reported to Microsoft
11th August 2026 – Microsoft releases update
6. About NCC Group
NCC Group is a global expert in cybersecurity and risk mitigation, working with businesses to protect their brand, value and reputation against the ever-evolving threat landscape. With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face. We are passionate about making the Internet safer and revolutionizing the way in which organizations think about cybersecurity.