Junglewise Threat Intelligence

CVE-2026-50296: Microsoft Windows Graphics Kernel privilege escalation

CVE-2026-50296 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 25H2, Microsoft Windows 11 Version 24H2, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 21H2, Microsoft Windows 11, Microsoft Windows 10 Version 22H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Graphics Kernel, a core component responsible for managing visual displays and hardware acceleration. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt operations.

Technical details

This vulnerability is a use-after-free (CWE-416) located within the Windows Graphics Kernel. An attacker with low-privileged local access can exploit this flaw by triggering a race condition or specific memory management sequence that accesses memory after it has been freed. Successful exploitation allows the attacker to execute code in kernel mode, leading to a full local privilege escalation (LPE). The attack requires local access and has a high complexity (AC:H) according to the vendor's CVSS assessment. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607 < 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 < 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 < 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 < 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 < 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 < 10.0.26100.8875
  • Microsoft Windows 11 version 26H1 < 10.0.28000.2525
  • Microsoft Windows Server 2016 < 10.0.14393.9339

Timeline

  • 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available via Microsoft MSRC.

References

Related threats