Vendor: Microsoft
Vendor URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69508
Versions affected: See MSRC advisory
Systems Affected: Microsoft Windows
Author: Alex Plaskett
Risk: Medium – Local Elevation of Privilege
Methodology: Agentic Vulnerability Identification and Exploitation
1. Summary
The Windows MIDI Services kernel driver implements "looped" (cyclic) UMP streaming using a shared memory buffer and a one-page registers region holding two 32-bit values — ReadPosition and WritePosition. The registers page is created PAGE_READWRITE and is mapped into the user-mode process that opens the streaming pin. The kernel StreamEngine uses those two values directly as byte offsets into the kernel-side buffer mapping with no bounds check against the buffer size as follows:
// MidiOut (read) path — StreamEngine.cpp:214
startingReadAddress = (PBYTE)BufferBase + midiOutReadPosition; // OOB: no < m_BufferSize check
dataSize = ((PUMPDATAFORMAT)startingReadAddress)->ByteCount; // OOB READ (:216)
// MidiIn (write) path — StreamEngine.cpp:406-413
startingWriteAddress = (PBYTE)BufferBase + midiInWritePosition; // OOB: no < m_BufferSize check
RtlCopyMemory(startingWriteAddress, pBuffer, bufferSize); // OOB WRITE (device-supplied content)
Because the position values are fully controlled by the (lower-trust) process that opened the pin, this yields a kernel relative write (with device-supplied content) and an out-of-bounds read dereference, each within a ~4 GB window above the buffer's kernel base address. A standard, non-administrator user can reach this by opening the driver's KS streaming pin directly (the KSCATEGORY_AUDIO interface is accessible to standard users).
Confirmed impact is a reliable standard-user kernel denial of service plus a standard-user kernel memory-corruption (relative write) primitive; escalation to SYSTEM is plausible but is not turnkey from this issue alone because the read result is not recoverable (no practical KASLR-defeat). Note: the read result is not exfiltrable (the forward path UMP-parses the bytes).
2. Vulnerability Details
The code for this driver is available at: github.com/microsoft/MIDI
The vulnerabilities were identified at src/api/Drivers/USBMIDI2/Driver/ (reviewed at commit 766b7e581a8d832adca83648a36a8cda8058c02b):
The looped-streaming design shares a producer/consumer ring with a lower-trust principal and trusts
the ring positions that principal writes:
- StreamEngine::GetLoopedStreamingRegisters (StreamEngine.cpp:1142-1178) allocates a one-page
registers region and maps it UserMode; m_ReadRegister / m_WriteRegister point at offsets 0/4
of that page. The page is created PAGE_READWRITE (see CreateMappedRegisters →
CreateMappedBuffer → CreateFileMapping(..., PAGE_READWRITE, ...), and the handle is handed
to the pin-opening process. The opener can therefore write arbitrary 32-bit ReadPosition / WritePosition values. - The kernel consumer reads those values once per pass and uses them as byte offsets into the kernel buffer mapping without validating, position < m_BufferSize:
- MidiOut: BufferBase + ReadPosition is dereferenced to read a UMPDATAFORMAT header
(ByteCount) and then ByteCount bytes are forwarded (StreamEngine.cpp:214/216/243-246).
- MidiIn: device-supplied UMP is written at BufferBase + WritePosition
(StreamEngine.cpp:406-413). The "space available" check (StreamEngine.cpp:362-387) is computed
from the same attacker-controlled positions, so it does not bound the destination.
Both ReadPosition / WritePosition are 32-bit, zero-extended and added to the 64-bit kernel base, giving a forward window of up to 0xFFFFFFFF (≈4 GB) above BufferBase.
3. Vendor Communication
8th June 2026 – Issue reported to Microsoft
8th September 2026 – Microsoft releases update
4. About NCC Group
NCC Group is a global expert in cybersecurity and risk mitigation, working with businesses to protect their brand, value and reputation against the ever-evolving threat landscape. With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face. We are passionate about making the Internet safer and revolutionizing the way in which organizations think about cybersecurity.