Junglewise Threat Intelligence

CVE-2026-50359: Microsoft XML Core Services use after free privilege escalation

CVE-2026-50359 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 25H2, Microsoft Windows 11 Version 24H2, Microsoft Windows 10 Version 22H2, Microsoft XML Core Services, Microsoft Windows Server 2012, Microsoft Windows 11 Version 26H1, Microsoft Windows 10 Version 1607, Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 1809. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft XML Core Services, a component used by Windows to process XML data. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to take full control of the affected system, potentially leading to data theft or the installation of malicious software.

Technical details

A use-after-free vulnerability (CWE-416) exists in Microsoft XML Core Services (MSXML). The flaw is triggered when the system improperly handles objects in memory, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the system with low-level user privileges. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining full system control. The attack complexity is rated as high, suggesting specific timing or environmental conditions are required for a successful exploit.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
  • Microsoft Microsoft XML Core Services (MSXML)

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats