Exposure of Sensitive System Information to an Unauthorized Control Sphere in Microsoft Windows - CVE-2026-68842

 

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Microsoft Windows - CVE-2026-68842

Published: September 8, 2026


Vulnerability identifier: #VU147505
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68842
CWE-ID: CWE-497
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module when accessing the service locally. A local user can exploit the vulnerability to disclose sensitive information.

Successful exploitation allows viewing heap memory from a privileged process running on the server.


Affected software

Microsoft Windows

How to mitigate CVE-2026-68842

Install security update from vendor's website.

Microsoft Windows - addressed in versions 11 24H2 10.0.26100.9445, 11 25H2 10.0.26200.9445, 11 26H1 10.0.28000.2954

External References

Related Security Bulletins