Junglewise Threat Intelligence

CVE-2026-50450: Microsoft Windows WWAN Service race condition privilege escalation

CVE-2026-50450 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows service responsible for managing wireless wide area network (cellular) connections. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or disrupt operations.

Technical details

A race condition (CWE-362) exists in the Windows Wireless Wide Area Network Service due to improper synchronization when accessing shared resources. An authorized attacker with low-level local access can exploit this timing-based vulnerability to execute code with elevated privileges. The attack requires the attacker to win a race condition, making the complexity high, but successful exploitation results in a scope change (S:C) allowing for full system compromise. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD
  • 2026-07-14: advisory

References

Related threats