Impact
The CVE-2026-50478 vulnerability is a use‑after‑free condition in the Windows kernel that permits an authorized local attacker to gain elevated privileges. This flaw is identified as CWE‑416 and can lead to unauthorized privilege escalation when an attacker is able to trigger the freed memory reuse.
Affected Systems
The vulnerability affects Microsoft Windows 10 1809 and 21H2 only on x86, Windows 10 22H2 on x64, Windows 11 24H2 and 25H2 on ARM64, and Windows 11 26H1 on x64. Windows Server 2019, 2022, and 2025, including Server Core installations, are also impacted across all supported processor architectures.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% signals a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Based on the description, it is inferred that the attacker must already have local user access and enough authority to apply the use‑after‑free flaw, meaning the attack vector is local and requires an authorized user.
OpenCVE Enrichment