Junglewise Threat Intelligence

CVE-2026-49173: Microsoft Windows Kernel use after free privilege escalation

CVE-2026-49173 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Kernel, the core component of the Microsoft Windows operating system. This flaw allows a user who already has basic access to a computer to gain full administrative control over the system. If exploited, an attacker could bypass security restrictions, access sensitive data, or install malicious software that would otherwise be blocked.

Technical details

A use-after-free (UAF) vulnerability exists in the Windows Kernel (CWE-416). The flaw is triggered when the kernel improperly handles objects in memory, allowing an attacker to reference memory after it has been freed. An attacker with local access and low-level privileges can exploit this condition to execute code in kernel mode. Successful exploitation results in a complete compromise of the system's integrity, confidentiality, and availability by granting the attacker SYSTEM-level privileges. Microsoft has released updates to address this issue in Windows 11 version 26H1.

Affected products

  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available via MSRC.

References

Related threats