Description
Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow in the Windows Web Proxy Auto‑Discovery Protocol (WPAD) that can be triggered by a local, authorized attacker interacting with WPAD services. The flaw allows memory corruption and the elevation of local user privileges to administrative levels, as the out‑of‑bounds write is a classic CWE‑122 condition. This gives the attacker the ability to change or delete data, install malware, or hijack the system, compromising confidentiality, integrity, and availability.

Affected Systems

Microsoft Windows 10 Version 1607, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016, including both standard and Server Core installations, are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity impact, while the EPSS score of less than 1% suggests a low incident probability at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local, authorized access and likely involves manipulating WPAD discovery traffic over the local network, limiting the risk to environments where WPAD is enabled and locally authenticated users are present.

Generated by OpenCVE AI on July 31, 2026 at 07:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE‑2026‑50480 via Windows Update or the Microsoft Security Response Center advisory.
  • Disable WPAD auto‑discovery through group policy or registry edits to prevent the vulnerable protocol from being used.
  • Block outgoing DNS requests or HTTP traffic used for WPAD by configuring the local firewall to restrict the relevant ports and protocols.

Generated by OpenCVE AI on July 31, 2026 at 07:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
Title Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Weaknesses CWE-122
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows Server 2012
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows Server 2012 Windows Server 2012 R2 Windows Server 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:06.805Z

Reserved: 2026-06-04T18:59:53.336Z

Link: CVE-2026-50480

cve-icon Vulnrichment

Updated: 2026-07-14T19:39:43.286Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:45:12Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow