Junglewise Threat Intelligence

CVE-2026-50347: Microsoft Windows heap overflow in Data DLL

CVE-2026-50347 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in a core Windows data processing component used across various versions of the operating system. An attacker who successfully tricks a user into opening a specially crafted file or running a malicious application could take full control of the affected computer. This could lead to the theft of sensitive data, installation of unauthorized software, or disruption of business operations.

Technical details

A heap-based buffer overflow (CWE-122) and integer overflow (CWE-190) exist in the Windows Data DLL component. The vulnerability is triggered when the system processes malformed data, leading to memory corruption. While the attack vector is local, it requires no prior privileges (PR:N) but does require user interaction (UI:R), such as a user opening a malicious file. Successful exploitation allows for arbitrary code execution with the privileges of the calling process. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server 2012 versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats