Description
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Windows Media contains a use‑after‑free flaw that, when triggered by an authorized local user, can elevate the attacker’s privileges on the target machine. The vulnerability is classed as CWE‑416 (Use After Free) and CWE‑362 (Race Condition), indicating that memory corruption can occur during the normal operation of the component.

Affected Systems

Microsoft Windows 11 version 24H2, 25H2, and 26H1 are affected. Builds 24H2 and 25H2 target arm64 devices, while 26H1 applies to x64 architecture.

Risk and Exploitability

The CVSS score of 7.8 denotes high severity, and the EPSS score of less than 1 % suggests that widespread exploitation is presently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a local user with an authorized account who can interact with the Windows Media component; only such users can exploit the flaw to gain elevated privileges.

Generated by OpenCVE AI on August 1, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses the Windows Media use‑after‑free flaw for Windows 11 24H2, 25H2, or 26H1.
  • If Windows Media is not required for the system’s functionality, uninstall or disable the component to reduce the attack surface.
  • Employ least‑privilege principles for user accounts so that local users have only the permissions necessary for their roles, minimizing the potential impact if the flaw is exploited.

Generated by OpenCVE AI on August 1, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Title Windows Media Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:36.155Z

Reserved: 2026-06-05T14:35:07.079Z

Link: CVE-2026-50677

cve-icon Vulnrichment

Updated: 2026-07-14T19:15:54.003Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:45:03Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free