Skip to navigation Skip to main content Skip to footer

Technical Advisory: Microsoft Windows – Windows MIDI Services (USBMIDI2.sys) – CVE-2026-69508

By Alex Plaskett

09 October 2026

Vendor: Microsoft    
Vendor URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69508
Versions affected: See MSRC advisory
Systems Affected: Microsoft Windows
Author: Alex Plaskett 
Risk: Medium – Local Elevation of Privilege
Methodology: Agentic Vulnerability Identification and Exploitation

 

1. Summary

The Windows MIDI Services kernel driver implements "looped" (cyclic) UMP streaming using a shared memory buffer and a one-page registers region holding two 32-bit values — ReadPosition and WritePosition. The registers page is created PAGE_READWRITE and is mapped into the user-mode process that opens the streaming pin. The kernel StreamEngine uses those two values directly as byte offsets into the kernel-side buffer mapping with no bounds check against the buffer size as follows:

// MidiOut (read) path — StreamEngine.cpp:214
startingReadAddress = (PBYTE)BufferBase + midiOutReadPosition;        // OOB: no  < m_BufferSize  check
dataSize = ((PUMPDATAFORMAT)startingReadAddress)->ByteCount;          // OOB READ (:216)

// MidiIn (write) path — StreamEngine.cpp:406-413
startingWriteAddress = (PBYTE)BufferBase + midiInWritePosition;       // OOB: no  < m_BufferSize  check
RtlCopyMemory(startingWriteAddress, pBuffer, bufferSize);             // OOB WRITE (device-supplied content)

Because the position values are fully controlled by the (lower-trust) process that opened the pin, this yields a kernel relative write (with device-supplied content) and an out-of-bounds read dereference, each within a ~4 GB window above the buffer's kernel base address. A standard, non-administrator user can reach this by opening the driver's KS streaming pin directly (the KSCATEGORY_AUDIO interface is accessible to standard users).

Confirmed impact is a reliable standard-user kernel denial of service plus a standard-user kernel memory-corruption (relative write) primitive; escalation to SYSTEM is plausible but is not turnkey from this issue alone because the read result is not recoverable (no practical KASLR-defeat). Note: the read result is not exfiltrable (the forward path UMP-parses the bytes). 

 

2. Vulnerability Details

The code for this driver is available at: github.com/microsoft/MIDI

The vulnerabilities were identified at src/api/Drivers/USBMIDI2/Driver/ (reviewed at commit 766b7e581a8d832adca83648a36a8cda8058c02b):

The looped-streaming design shares a producer/consumer ring with a lower-trust principal and trusts
the ring positions that principal writes:

  1. StreamEngine::GetLoopedStreamingRegisters (StreamEngine.cpp:1142-1178) allocates a one-page
       registers region and maps it UserMode; m_ReadRegister / m_WriteRegister point at offsets 0/4
       of that page. The page is created PAGE_READWRITE (see CreateMappedRegisters →
       CreateMappedBuffer → CreateFileMapping(..., PAGE_READWRITE, ...), and the handle is handed
       to the pin-opening process. The opener can therefore write arbitrary 32-bit ReadPosition / WritePosition values.
  2. The kernel consumer reads those values once per pass and uses them as byte offsets into the kernel buffer mapping without validating, position < m_BufferSize:
       - MidiOut: BufferBase + ReadPosition is dereferenced to read a UMPDATAFORMAT header
         (ByteCount) and then ByteCount bytes are forwarded (StreamEngine.cpp:214/216/243-246).
       - MidiIn: device-supplied UMP is written at BufferBase + WritePosition
         (StreamEngine.cpp:406-413). The "space available" check (StreamEngine.cpp:362-387) is computed
         from the same attacker-controlled positions, so it does not bound the destination.
    Both ReadPosition / WritePosition are 32-bit, zero-extended and added to the 64-bit kernel base, giving a forward window of up to 0xFFFFFFFF (≈4 GB) above BufferBase.

3. Vendor Communication

8th June 2026 – Issue reported to Microsoft
8th September 2026 – Microsoft releases update

 
4. About NCC Group


NCC Group is a global expert in cybersecurity and risk mitigation, working with businesses to protect their brand, value and reputation against the ever-evolving threat landscape. With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face. We are passionate about making the Internet safer and revolutionizing the way in which organizations think about cybersecurity.