Description
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Windows Secure Kernel Mode lets a local, authorized attacker raise privileges to Administrator or SYSTEM. The vulnerability is a classic memory corruption error that bypasses normal access controls, enabling the attacker to load malicious code with kernel privileges. Once escalated, the attacker can manipulate system settings, install software, or read and modify protected data, potentially compromising the entire machine.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (both regular and Server Core installations). The affected architectures include arm64 for the 24H2 and 26H1 releases and x64 for the 25H2 release.

Risk and Exploitability

The CVSS score of 7.0 indicates a severe impact. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. However, the attack requires local access and an authorized user context, which means any user with legitimate access could potentially leverage the flaw. The combination of high severity and low exploitation probability places the risk in the moderate category, but organizations should not delay remediation.

Generated by OpenCVE AI on July 31, 2026 at 08:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update as detailed on the Microsoft Security Response Center, which patches the vulnerable kernel code.
  • If the update cannot be applied immediately, enforce least‑privilege policies and remove local administrative rights from users to reduce the attack surface.
  • Consider segmenting workloads that run on the affected Windows versions to isolate critical services until the patch is deployed.

Generated by OpenCVE AI on July 31, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Title Windows Secure Kernel Mode Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:23:58.151Z

Reserved: 2026-06-04T18:55:14.745Z

Link: CVE-2026-50392

cve-icon Vulnrichment

Updated: 2026-07-15T10:43:29.198Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:45:17Z

Weaknesses