Junglewise Threat Intelligence

CVE-2026-50335: Microsoft Windows privilege escalation via improper access control

CVE-2026-50335 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in several versions of the Microsoft Windows operating system that could allow a user with basic access to gain full administrative control. This type of flaw is often used by attackers who have already gained a foothold on a system to deepen their access and compromise sensitive data or install persistent malware. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server editions.

Technical details

A local privilege escalation vulnerability exists in Microsoft Windows due to improper access control (CWE-284). An attacker who is already authenticated to a vulnerable system with low-level user privileges can exploit this flaw to gain SYSTEM-level permissions. The attack vector is local, requiring the attacker to execute a specially crafted application on the target machine. The vulnerability affects a wide range of Windows versions, including Windows 10, Windows 11, and Windows Server 2019/2022. Microsoft has released patches to remediate this issue as part of their July 2026 update cycle.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available by Microsoft.

References

Related threats