CVE-2026-62693ImportantRevised 9 Sep
Windows MIDI Service Module Elevation of Privileges Vulnerability
Assessment
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
- Severity
- Important
- CVSS base score
- 7.0CVSS:3.1/
AV:L/ AC:H/ PR:L/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.2%Higher than 9.1% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Unlikely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Windows MIDI Service Module
- Weakness
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- Issued by
- Microsoft
- Published
- 11 Aug 2026 · August 2026
- Last revised
- 9 Sep 2026Updated an acknowledgement. This is an informational change only.
Updates that fix it
3 KBs| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5120994 | Security Hotpatch Update | Required | Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems and 1 more | All CVEs in KB5120994 |
| KB5121000 | Security Update | Required | Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems | All CVEs in KB5121000 |
| KB5121003 | Security Update | Required | Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems and 1 more | All CVEs in KB5121003 |
Affected products
Windows6 affected products
- Windows 11 Version 24H2 for ARM64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows 11 Version 25H2 for ARM64-based Systems
- Windows 11 Version 25H2 for x64-based Systems
- Windows 11 Version 26H1 for ARM64-based Systems
- Windows 11 version 26H1 for x64-based Systems