Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Windows Media contains a race condition involving shared resources that can be exploited by an authorized attacker to elevate privileges over a network. The flaw lies in improper synchronization when concurrent operations access the media subsystem, allowing the attacker to perform actions as a higher‑privileged user. The associated weaknesses include CWE‑362, a race condition, and CWE‑416, use‑after‑free. This can lead to execution of code with elevated rights, potentially enabling broader system compromise.

Affected Systems

Affected are Microsoft Windows 11 releases 24H2, 25H2, and 26H1, as well as Windows Server 2025, including Server Core installations. The vulnerability is present in the Windows Media component of these operating system versions.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact vulnerability, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV archive, and the attack vector is inferred to be over a network requiring the attacker to have some authorized presence. Exploitation would hinge on the attacker triggering the race condition in the media subsystem to gain elevated privileges.

Generated by OpenCVE AI on July 31, 2026 at 08:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows security update that addresses CVE-2026-50414 as soon as it becomes available.
  • Disable or limit Windows Media Player and related media services on servers and managed workstations that do not require them.
  • Configure network firewalls to block or restrict traffic to media services that could expose the vulnerable component to unauthorized remote access.

Generated by OpenCVE AI on July 31, 2026 at 08:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
Title Windows Media Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:17.350Z

Reserved: 2026-06-04T18:56:53.259Z

Link: CVE-2026-50414

cve-icon Vulnrichment

Updated: 2026-07-15T10:46:00.831Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:15:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free