Impact
CVE‑2026‑50436 is a use‑after‑free flaw in a Windows kernel component that allows an attacker who can run code with local user privileges to gain kernel‑level control. The vulnerability is classified as CWE‑416, indicating that freed memory can be accessed after it has been released, enabling arbitrary memory reads and writes. Successful exploitation elevates the attacker’s privileges to that of the system, allowing installation of malware, creation of rootkits, or modification of critical system settings.
Affected Systems
Affected versions include Microsoft Windows 11 24H2, 25H2, and 26H1 as well as Windows Server 2025 and Windows Server 2025 (Server Core). The 24H2 and 25H2 releases are impacted on arm64 architectures, while the 26H1 release is affected on x64. All Server 2025 builds, regardless of architecture, are also vulnerable.
Risk and Exploitability
The CVSS score of 7.8 labels this flaw as high severity. An EPSS score of 2 % indicates a moderate likelihood of exploitation, though the vulnerability is not yet listed in the CISA KEV catalog, implying no known public exploits. Because the flaw requires local code execution, it is considered a local privilege escalation risk; an attacker would need to execute malicious code on the target machine, after which the use‑after‑free allows kernel escalation.
OpenCVE Enrichment