Junglewise Threat Intelligence

CVE-2026-50377: Microsoft Windows Kernel out-of-bounds read privilege escalation

CVE-2026-50377 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Kernel could allow a user who is already logged into a system to gain higher-level access than they should have. The Windows Kernel is the core part of the operating system that manages hardware and software interactions. If exploited, an attacker could potentially access sensitive information or perform actions reserved for administrators, compromising the security of the device.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Windows Kernel. The flaw is triggered when the kernel improperly handles memory access, allowing a locally authenticated attacker with low privileges to read data from memory locations outside of the intended buffer. This can lead to the disclosure of sensitive kernel-mode information, which an attacker can leverage to elevate their privileges on the local system. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2016. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
  • 2026-07-14: advisory: Microsoft Security Update Guide entry created.

References

Related threats