Junglewise Threat Intelligence

CVE-2026-50329: Microsoft Windows Kernel privilege escalation via use after free

CVE-2026-50329 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Kernel, the core component of the Microsoft Windows operating system. This flaw allows a user who already has basic access to a computer to gain full administrative control. If exploited, an attacker could bypass security restrictions to install programs, view or delete sensitive data, or create new accounts with full user rights.

Technical details

A use-after-free (UAF) vulnerability exists in the Windows Kernel (CWE-416). The flaw is triggered when the kernel continues to use a pointer after it has been freed, leading to memory corruption. An attacker with local access and low-level privileges can exploit this vulnerability to execute code in kernel mode. Successful exploitation results in local privilege escalation (LPE), granting the attacker SYSTEM-level authority. The vulnerability is reachable via local attack vectors and does not require user interaction. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats