Junglewise Threat Intelligence

CVE-2026-50311: Microsoft Windows improper access control privilege escalation

CVE-2026-50311 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability in Microsoft Windows and Windows Server could allow a user with basic access to gain full administrative control over the system. This type of flaw is often used by attackers who have already gained a foothold on a network to expand their reach and compromise sensitive data or critical infrastructure. Microsoft has released security updates to address this issue across affected versions of the operating system.

Technical details

A local privilege escalation vulnerability exists in Microsoft Windows and Windows Server due to improper access control (CWE-284). An attacker with low-privileged local access can exploit this flaw to gain SYSTEM-level privileges without any user interaction. The vulnerability affects a wide range of Windows versions, including Windows 10, Windows 11, and Windows Server 2012. Microsoft has addressed this issue in the July 2026 security updates; administrators should apply the relevant patches for their specific OS build.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats