Junglewise Threat Intelligence

CVE-2026-50307: Microsoft Windows TCP/IP use after free privilege escalation

CVE-2026-50307 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 11, Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows networking component (TCP/IP) that could allow a user with limited access to gain full administrative control over a computer. This component is responsible for how the computer communicates over networks and the internet. If exploited, an attacker who already has a foothold on the system could access sensitive data or disrupt operations by escalating their permissions.

Technical details

A use-after-free (CWE-416) vulnerability exists within the Windows TCP/IP stack. The flaw is triggered when the system incorrectly handles objects in memory during network operations, allowing an attacker to reuse memory that has already been freed. To exploit this, an attacker must first have local access to the system with low-level user privileges. Successful exploitation enables the attacker to execute code with elevated privileges, potentially gaining SYSTEM-level access. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats