Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.