Description
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
Published: 2026-07-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw in Windows System that permits an unauthorized local attacker to bypass a security feature. By bypassing the intended protection, the attacker can potentially gain unauthorized permissions or alter system state, compromising system integrity and possibly confidentiality. The weakness is classified as CWE‑284.

Affected Systems

Affected products include Microsoft Windows 11 24H2, 25H2, and 26H1 across ARM64 and x64 architectures, as well as Microsoft Windows Server 2022 and Window Server 2025, including Server Core installations.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity vulnerability with a low but non-zero exploitation probability (EPSS < 1%). The issue is not listed in the CISA KEV catalog. The likely attack vector is local, meaning an attacker must be present on the affected machine to leverage this flaw. While the vulnerability does not grant full privilege escalation by itself, it enables bypassing an important security measure that could lead to further compromise if combined with other local privilege escalation techniques.

Generated by OpenCVE AI on July 31, 2026 at 08:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Windows cumulative update that contains the fix for this issue from the Microsoft Security Update Guide.
  • If a patch is not yet available for your environment, temporarily disable or restrict the affected security feature until the update is released.
  • Review local group policy and application configurations to enforce least privilege and monitor for unauthorized changes.

Generated by OpenCVE AI on July 31, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
Title Windows System Secure Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-284
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:24:35.719Z

Reserved: 2026-06-04T18:56:53.259Z

Link: CVE-2026-50418

cve-icon Vulnrichment

Updated: 2026-07-15T13:35:14.550Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:15:04Z

Weaknesses