Description
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in certain Windows kernel‑mode drivers allows an authorized user to execute code after memory has already been freed. This can grant the attacker higher privileges on the system. The weakness is identified as CWE‑416 and directly undermines operating‑system integrity.

Affected Systems

Microsoft Windows 11 24H2, 25H2, and 26H1 and Windows Server 2025, including Server Core, are affected; the 24H2 and 25H2 builds are vulnerable on arm64, while the 26H1 build is affected on x64.

Risk and Exploitability

The CVSS base score of 7 indicates medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local: a user or process with sufficient privileges to interact with the faulty driver can trigger the flaw. Based on the description, it is inferred that no public exploit has been observed.

Generated by OpenCVE AI on August 1, 2026 at 09:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that fixes the kernel‑mode driver issue (refer to the MSRC advisory).
  • Segregate local accounts to only the privileges required for their functions and remove unnecessary administrative rights.
  • If the vulnerable driver is nonessential, disable or restrict its execution on the affected systems.

Generated by OpenCVE AI on August 1, 2026 at 09:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Title Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:24:11.085Z

Reserved: 2026-06-04T18:55:14.746Z

Link: CVE-2026-50396

cve-icon Vulnrichment

Updated: 2026-07-15T10:35:44.452Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:45:03Z

Weaknesses