Exposure of Sensitive System Information to an Unauthorized Control Sphere in Microsoft Windows - CVE-2026-69339
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module when accessing the service locally. A local user can access the service to disclose sensitive information.
Successful exploitation allows viewing heap memory from a privileged process running on the server.