Junglewise Threat Intelligence

CVE-2026-50452: Microsoft Windows Runtime privilege escalation via race condition

CVE-2026-50452 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Runtime, a core component of the Windows operating system that allows applications to interact with the system. An attacker could exploit this flaw to gain higher-level system permissions than they should normally have. If successful, this could allow an unauthorized user to interfere with system operations or access restricted data across a network.

Technical details

A race condition (CWE-362) exists in the Windows Runtime (WinRT) due to improper synchronization when accessing shared resources. The vulnerability may also involve a use-after-free (CWE-416) condition triggered during concurrent execution. An unauthenticated attacker can exploit this over the network, though the attack complexity is high due to the precise timing required to win the race condition. Successful exploitation allows for elevation of privilege, potentially granting the attacker unauthorized access or the ability to impact system availability. Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server to address this issue.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: advisory

References

Related threats