Description
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: 3.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper access control in the Windows Win32K subsystem, allowing an entity with local authorization to elevate its privileges. The result is that a user who can execute code on a target machine may gain higher privileges than intended, potentially compromising system integrity and confidentiality.

Affected Systems

Affected are Microsoft Windows 10 from Version 1607 through 22H2 and Windows 11 from Version 24H2 through 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations. These include both 32‑bit and 64‑bit platforms as listed in the vendor/deployment matrix.

Risk and Exploitability

The high‑severity local privilege escalation reflected by the CVSS score of 7, coupled with an EPSS score of 3%, indicates a moderate probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread attacks have been observed. An attacker must already have local access or a sufficient user context to leverage the improper access control in the Win32K subsystem, thereby gaining higher privileges and potentially compromising the integrity and confidentiality of the affected system.

Generated by OpenCVE AI on July 31, 2026 at 08:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the security update released by Microsoft for CVE-2026-49805 on all affected Windows 10, Windows 11, and Windows Server 2012‑2025 releases as specified in the vendor’s advisory.
  • Apply the patch to both full and Server Core installations to ensure coverage across all deployment types.
  • Limit user privileges on systems until the update is deployed, reducing the potential impact of an unpatched local attacker.

Generated by OpenCVE AI on July 31, 2026 at 08:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
Title Win32k Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-284
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:54:27.667Z

Reserved: 2026-06-01T17:02:37.208Z

Link: CVE-2026-49805

cve-icon Vulnrichment

Updated: 2026-07-14T18:11:10.033Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:00:07Z

Weaknesses