Exposure of Sensitive System Information to an Unauthorized Control Sphere in Microsoft Windows - CVE-2026-68842
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module when accessing the service locally. A local user can exploit the vulnerability to disclose sensitive information.
Successful exploitation allows viewing heap memory from a privileged process running on the server.