Description
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in Windows kernel‑mode drivers that allows an authorized local user to gain elevated privileges by accessing memory that has already been freed. This misuse of memory can lead to arbitrary kernel‑level code. The improper freeing of resources after use.

Affected Systems

Affected systems include Microsoft Windows 11 24H2 and 25H2 ARM64 builds, Windows 11 26H1 x64 build, and Windows Server 2025 in both standard and Server Core installations. All current releases of these platforms remain vulnerable until Microsoft releases an official update.

Risk and Exploitability

The CVSS score of 7 marks the issue as high severity. With an EPSS score of less than 1 % and no listing in the CISA KEV catalog, widespread exploitation is considered unlikely but feasible for a local attacker. The likely attack vector is a trusted user who can load kernel‑mode drivers, which is then able to trigger the use‑after‑free and exploit it; based on the description, it is inferred that an attacker would need administrative or driver‑install privileges to carry out the exploit.

Generated by OpenCVE AI on July 31, 2026 at 08:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the cumulative Windows update from Microsoft that includes the fix for CVE‑2026‑50393.
  • Reboot the system after installing the update so the patched kernel drivers are loaded.
  • If a patch is not immediately available, restrict and monitor driver installation to approved drivers and remove any unapproved kernel‑mode drivers that could be used to exploit the flaw.

Generated by OpenCVE AI on July 31, 2026 at 08:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Title Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:24:00.988Z

Reserved: 2026-06-04T18:55:14.745Z

Link: CVE-2026-50393

cve-icon Vulnrichment

Updated: 2026-07-15T10:35:30.809Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:45:17Z

Weaknesses