Description
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a command injection vulnerability in the Windows Clipboard User Service. An attacker who can run applications in the user context can inject specially crafted input that is passed to a system command without proper neutralization, allowing the attacker to execute commands with elevated privileges. This could enable the attacker to gain full SYSTEM rights, compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

Microsoft Windows 11 24H2 and 25H2, both including ARM64 builds, as well as Windows Server 2025 in full and Server Core editions are affected. The vulnerability is specific to the Clipboard User Service component in these operating system releases.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score of <1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and an authorized user context, but the ability to elevate privileges to SYSTEM presents a high impact if the attacker is present on the machine.

Generated by OpenCVE AI on July 31, 2026 at 07:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update that addresses CVE-2026-50488 for the affected Windows binaries via Windows Update or the Microsoft Update Catalog.
  • If a patch cannot be applied immediately, disable the Clipboard User Service to prevent its elevated‑privilege functionality from executing.
  • Ensure that Windows Update is enabled and that future security patches are installed promptly to protect against newly discovered vulnerabilities.

Generated by OpenCVE AI on July 31, 2026 at 07:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.
Title Clipboard User Service Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows Server 2025
Weaknesses CWE-77
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:22.949Z

Reserved: 2026-06-04T18:59:53.336Z

Link: CVE-2026-50488

cve-icon Vulnrichment

Updated: 2026-07-15T10:48:16.938Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:45:12Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')