Description
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free in the Windows kernel that is triggered by manipulating Win32k objects. It is classified as CWE‑416. If an attacker who is already authenticated on the machine can exploit this race condition, they can elevate their privileges to administrator or SYSTEM, thereby gaining the ability to execute arbitrary code, modify protected system files, or obtain sensitive information.

Affected Systems

Microsoft Windows 11 versions 24H2, 25H2, and 26H1 and Windows Server 2025, including Server Core installations, are affected. The CNA lists both ARM64 and x86‑64 architectures for the Windows 11 releases and the server build, indicating that the vulnerability is present across the available hardware platforms.

Risk and Exploitability

The CVSS score of 8.8 signals a high‑severity risk, yet the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not part of the CISA KEV catalog. The attack likely requires a local user who can run code, such as a standard or administrator account, because the use‑after‑free is triggered from a user‑mode context. With successfully elevated privileges, an attacker could maintain persistent access or pivot to higher privileges within the system.

Generated by OpenCVE AI on July 31, 2026 at 07:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update for CVE‑2026‑50687 to Windows 11 (24H2, 25H2, 26H1) and Windows Server 2025, including Server Core installations.
  • If patching cannot be performed immediately, limit local user privileges by enforcing least privilege; restrict accounts that have access to Win32k components and disable unnecessary local services that could expose the kernel to the race condition.
  • Deploy and configure an endpoint protection solution such as Windows Defender Advanced Threat Protection or a comparable EDR, and monitor for privilege‑escalation indicators such as sudden SYSTEM privilege acquisition or suspicious access to kernel objects.

Generated by OpenCVE AI on July 31, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Title Windows Win32k Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:53.638Z

Reserved: 2026-06-05T14:35:07.080Z

Link: CVE-2026-50687

cve-icon Vulnrichment

Updated: 2026-07-15T10:49:10.939Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses