Junglewise Threat Intelligence

CVE-2026-50350: Microsoft Windows information disclosure in Trusted Runtime Interface Driver

CVE-2026-50350 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 25H2, Microsoft Windows 11 Version 24H2, Microsoft Windows 10 Version 22H2, Microsoft Windows 11 Version 26H1, Microsoft Windows Server 2025, Microsoft Windows 10 Version 21H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Trusted Runtime Interface Driver, a component that manages secure communication between the operating system and trusted hardware environments. An attacker who already has basic access to a computer could exploit this flaw to view sensitive information that should normally be protected. This could lead to the exposure of confidential system data, though it does not allow the attacker to take control of the machine or delete files directly.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Microsoft Windows Trusted Runtime Interface (TrEE) Driver. The flaw stems from improper access control or memory handling within the driver, which facilitates communication between the OS and Trusted Execution Environments (TEEs). An attacker with local access and low-level user privileges can exploit this vulnerability to disclose sensitive information from the kernel or secure runtime environment. The attack vector is local, requiring no user interaction. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server 2025.

Affected products

  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
  • 2026-07-14: patched: Security updates released by Microsoft.

References

Related threats