Junglewise Threat Intelligence

CVE-2026-49807: Microsoft Windows DirectX information disclosure

CVE-2026-49807 · Severity: medium · CVSS 6.2 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Windows DirectX, a collection of components used by the operating system to handle multimedia and graphics tasks. An attacker with local access to a system could exploit this flaw to view sensitive information that should otherwise be protected. While the attacker cannot take control of the system or delete files, the exposed data could be used to facilitate further, more complex attacks.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Microsoft Windows DirectX component. The flaw allows a local attacker to bypass security restrictions and gain access to sensitive information residing in memory or system files. The attack vector is local, meaning the attacker must already have the ability to execute code on the target machine, though no special privileges or user interaction are required. Successful exploitation results in a high impact on confidentiality but does not affect system integrity or availability. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats