Junglewise Threat Intelligence

CVE-2026-50323: Microsoft Windows Runtime use after free privilege escalation

CVE-2026-50323 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows Server 2025, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Runtime, a core component of the Windows operating system that helps applications run and interact with the system. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative permissions. This could allow them to bypass security restrictions, access sensitive data, or install malicious software that would otherwise be blocked.

Technical details

A use-after-free vulnerability (CWE-416) exists in the Windows Runtime (WinRT) component of Microsoft Windows. The flaw is triggered when the system continues to use a memory pointer after it has been freed, which can be manipulated by a local attacker with low privileges. Successful exploitation requires the attacker to win a race condition or navigate high complexity execution flow (AC:H) to achieve local privilege escalation (LPE). If successful, the attacker can gain SYSTEM-level privileges on the affected host. Microsoft has released security updates to address this issue across supported versions of Windows 11 and Windows Server 2025.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.26200.0 to 10.0.28000.2269
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats