Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from a race condition in the Windows Audio Service when concurrent operations access a shared resource without proper synchronization. Because a locally authenticated user can trigger the race, the attacker can obtain higher privileges on the affected Windows 11 systems. The flaw is classified under CWE-362 and CWE-416, indicating improper synchronization and potential use-after-free bugs, and the CVSS score of 7.8 reflects its high severity.

Affected Systems

Affected are Microsoft Windows 11 24H2 and 25H2 for the arm64 architecture, and Windows 11 26H1 for the x64 architecture. These versions are enumerated by their corresponding CPE strings and are listed as vulnerable by Microsoft.

Risk and Exploitability

The EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user who can trigger the race condition, so the attack surface is limited to environments where the Windows Audio Service runs. Because the flaw is a local privilege escalation, potential impact includes full system compromise by an attacker who can elevate privileges. The likely attack vector is local.

Generated by OpenCVE AI on July 31, 2026 at 08:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest cumulative update for Windows 11 that contains the fix for CVE‑2026‑50440 from Microsoft Security Response Center.
  • Reboot the computer to ensure the Windows Audio Service loads the updated binaries.
  • If the update cannot be applied immediately, restrict or disable the Windows Audio Service on computers that do not require audio functionality until the patch is available.

Generated by OpenCVE AI on July 31, 2026 at 08:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Title Windows Audio Service Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:24:07.139Z

Reserved: 2026-06-04T18:57:47.376Z

Link: CVE-2026-50440

cve-icon Vulnrichment

Updated: 2026-07-14T19:21:30.519Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:45:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free