Junglewise Threat Intelligence

CVE-2026-50316: Microsoft Windows Kernel information disclosure in log files

CVE-2026-50316 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 24H2, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability in the Windows Kernel could allow an authorized user to view sensitive information that has been improperly recorded in system log files. While an attacker must already have access to the system to exploit this, it could lead to the exposure of confidential data that should remain protected. Microsoft has released security updates to address this issue across affected versions of Windows and Windows Server.

Technical details

An information disclosure vulnerability exists in the Windows Kernel due to the improper insertion of sensitive information into log files (CWE-532). An attacker with local access and low-level privileges can exploit this by reading system logs to obtain sensitive data that was not intended for disclosure. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server. Microsoft has addressed this issue in the July 2026 security updates. Exploitation requires the attacker to have existing authorized access to the target system.

Affected products

  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats