Junglewise Threat Intelligence

CVE-2026-50356: Microsoft Windows App Store race condition privilege escalation

CVE-2026-50356 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 1607, Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 24H2, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Windows App Store that could allow a user with limited access to gain full administrative control over a computer. The issue is caused by a timing error when the system handles shared resources, which an attacker can exploit to bypass security restrictions. If successful, an attacker could install programs, view or delete sensitive data, or create new user accounts with full rights.

Technical details

A race condition vulnerability (CWE-362) exists in the Microsoft Windows App Store due to improper synchronization when accessing shared resources. An attacker with local access and low privileges can exploit this flaw by timing specific operations to interfere with concurrent executions. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining SYSTEM-level access. The attack requires the attacker to already have an authorized account on the local system, though the complexity is rated as high due to the precise timing required for a successful race condition. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server versions.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2016 10.0.14393.0 to 10.0.14393.9339

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates made available by Microsoft

References

Related threats