Junglewise Threat Intelligence

CVE-2026-50457: Microsoft Windows Runtime privilege escalation via use after free

CVE-2026-50457 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2025, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Runtime, a core component of the Windows operating system that handles application interactions. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free vulnerability (CWE-416) exists in the Windows Runtime component, often triggered by a race condition (CWE-362) during concurrent execution using shared resources. The flaw occurs when the system continues to use a memory pointer after it has been freed, which can be manipulated by an attacker. To exploit this, an attacker must first have local access to the target system with low-level user privileges. Successful exploitation allows the attacker to execute code with elevated system privileges, potentially leading to a full compromise of the host. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2025 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats