Junglewise Threat Intelligence

CVE-2026-50419: Microsoft Windows Kernel information disclosure

CVE-2026-50419 · Severity: low · CVSS 3.3 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability in the Windows Kernel could allow a user who is already logged into a computer to view sensitive information they are not authorized to see. The Windows Kernel is the core part of the operating system that manages hardware and system resources. While this flaw does not allow an attacker to take over the system or delete files, it could lead to the exposure of internal system data that could be used to facilitate further attacks.

Technical details

An information disclosure vulnerability exists in the Windows Kernel (CWE-200). The flaw is caused by the kernel improperly handling sensitive information, which can be accessed by an unauthorized actor. To exploit this, an attacker must first have local access to the target system and be able to execute a specially crafted application. Successful exploitation allows the attacker to disclose sensitive information from the kernel's memory space. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server 2012.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
  • 2026-07-14: advisory: Microsoft Security Response Center (MSRC) published the update guide.

References

Related threats